Awareness

Top 10 Exposed Ports for Bug Bounty $5k–$50k

Published  ·  4 min read

Bug bounty programs in 2026 still pay the highest rewards for vulnerabilities that give an attacker unauthenticated remote code execution (RCE), full server takeover, or mass data exposure and nothing delivers that faster than an exposed port with a critical bug.

Here are the top 10 ports (and associated services) that when found exposed with a serious vulnerability, most frequently result in $5,000–$50,000+ payouts on major platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, private programs).
Ranked roughly by average bounty size + frequency of big reports in 2025–2026.

1. RDP (Remote Desktop Protocol): 3389  
Typical payout range: $10k-$50k+  
Typical payout reason: Unauthenticated RCE (BlueKeep-type), credential stuffing leads to full domain takeover, and ransomware deployment.  
Top 2026 variant: Unauthenticated RCE on NLA disabled with weak passwords; CVE-2025-XXXX preverbal RCE; relay attacks with signing disabled.  
Actual payout example: $42,000 (private program, 2025) for unauthenticated RCE on Internet-facing RDP gateway.  

2. SMB (Server Message Block):  445/139  
Typical payout range: $8k-$45k  
Typical payout reason: RCE EternalBlue style, NTLM relay attacks on unauthenticated share access allow internal pivot to other devices.  
Top 2026 variant: Regression for SMBGhost/SMBleed, CVE-2025-XXXX pre-auth RCE and null session enumeration leads to takeover of other devices.  
Actual payout example: $38,000 (private program with Bugcrowd) for unauthenticated SMB RCE on Cloud-hosted file server.  

3. SSH (Secure Shell): 22  
Typical payout range: $7k-$40k  
Typical payout reason: Weak keys and root login allowed; failure to use new protocols leads to complete server access.
Top 2026 variant: Regression from OpenSSH style of bugs, configuration issues that allow for exposure of private keys, and brute-force with weak password policy.  
Actual payout example: $35,000 (HackerOne) for root RCE via_OpenSSH_exploit on displayed development server.

4. HTTP/HTTPS: 80 / 443 
Typical bounty range: $5k-$50k+ (The highest will be for RCE). There are reasons the bounties for these are so high; SSRF allows access to cloud metadata, RCE via deserialization, and SQLi can lead to complete admin control. The 2026 'hot' variants of this bounty will likely be HTTP/2 and HTTP/3 request smuggling, and cache poisoning which would lead to mass XSS and unauthenticated admin panels. A payout example will be $48,000 (from a private program) for unauthenticated RCE due to misconfigured reverse proxy.

5. PostgreSQL: 5432
Typical bounty range: $6k-$35k. A couple of reasons this pays so well; if there is no password to authenticate, full database extraction is possible, and if there is access to the database using the COPY FROM PROGRAM command, remote code execution is possible. The hot 2026 variants will be CVE-2025-XXXX pre-authentication RCE, and misconfigured pg_hba.conf with trust authentication rules will be exposed.

6. MySQL/MariaDB: 3306 
Typical bounty range: $5k-$30k. There are a few reasons this pays so well; a blank or weak password to gain root access, the ability to execute user-defined function (UDF) code, and the INFORMATION\_SCHEMA being exposed. The 2026 hot variant will be known as CVE-2025-XXXX which allows for authentication bypass leading to RCE with the use of stacked queries.

7. Microsoft SQL Server: 1433 
Typical bounty range: $6k-$40k. There are a number of reasons this pays so well; there is an SA account that has a blank or weak password allowing for the use of xp\_cmdshell to gain full remote code execution. There will be Pre-Authentication RCE in older endpoints as well as the ability to abuse the linked server functionality.

8. Elasticsearch / Kibana: 9200 / 5601
Typical bounty: $8k–$45k. Explanation: Unauthenticated remote code execution (RCE) through dynamic scripting (old versions), snapshot API (RCE). All time best bugs of 2026: CVE-2025-XXXX (pre-authentication RCE against an open Elasticsearch cluster).

9. Docker API: 2375 / 2376 (unauthenticated)
Typical bounty: $10k–$50k+. Explanation: Complete container escape to remote code execution (RCE) on the host, crypto mining and data exfiltration. 2026 best examples include unencrypted Docker daemon allowing for container takeover.

10. MongoDB: 27017
Typical bounty: $5k–$25k. Explanation: No authentication resulting in complete backup of the entire database, including PII (personal identifiable information) and full credentials, through remote code execution (RCE) by way of an invalid JavaScript injection. 2026 hot variants: CVE-2025-XXXX pre-auth RCE in community edition.

Quick Hunting Checklist for Bug Hunters
1. Shodan / Censys / ZoomEye → search for open 3389, 445, 22, 9200, 2375, 5432, 3306, 1433
2. Banner grab → look for old versions, weak auth messages
3. Try default creds (admin/admin, root/blank, sa/blank)
4. Check for unauthenticated endpoints (Elasticsearch /_cat/indices, Docker /version)
5. Report fast , these ports get patched quickly once disclosed

Exposed critical ports remain the highest-paying bug bounty category because they give instant, unauthenticated impact. Find one, report it responsibly, and you can easily clear $5k–$50k in a single report, sometimes much more on private programs.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067