There are various security broker companies that governments work with. An unscrupulous pentester could find one, email them, and ask them if they're interested.
The trouble would be how to prove the exploit works without also revealing how it's done. The best bet would be to demo one or two out of the three exploits required to work, then talk business in exchange for the third.