okay, when would you need to purchase a 0day vulnerability from someone else to exploit thousands of other systems as part of legitimate system engineering?
Well, if working for a company where you are in charge of the security of thousands of systems, you might be asked to do exactly this.
If I was running a massive company, I would want my network security team to be buying up the latest cracking tech and checking it against as much of the corporate systems as possible.
Any corporation with any sense and lots of stuff they need to secure pays people to attack their corporate networks with anything and everything available, and then report back.