What Is a Zero-Day Vulnerability?

Also called: Zero-day, 0-day

Related problems: A vendor announced a critical flaw with no patch yet; Worried about attacks our antivirus has never seen before; Not sure how fast we could react to an emergency security bulletin

A zero-day vulnerability is a security flaw in software, firmware or hardware that attackers know about, or can use, before the vendor has released a fix. The name comes from the defender’s position: the vendor and its customers have had “zero days” to prepare a patch. Zero-days are prized by attackers because standard defenses such as patching and signature-based antivirus are not yet ready for them.

At a glance

  • A zero-day is a flaw with no available fix at the time attackers start using it or it becomes public.
  • The vulnerability is the flaw; the exploit is the code that uses it; a zero-day attack is the exploit used against real targets.
  • Patching cannot help until a fix exists, so defense relies on mitigations, limiting exposure and detecting suspicious behavior.
  • Internet-facing systems such as VPN appliances, firewalls, email servers and file-transfer tools are frequent targets.
  • Once a patch ships, the race shifts to how quickly you can apply it.

What problem it solves

A zero-day is a problem, not a solution, but understanding the term helps buyers plan for one of the hardest situations in security. Most security programs are built around known weaknesses: scanners find missing patches, and patch management applies them. A zero-day breaks that cycle, because there is nothing to scan for and nothing to install yet.

For mid-sized organizations, the practical question is not whether they can prevent every zero-day, which no one can, but how quickly they can find out they are affected, reduce exposure and detect an intruder who got in through one. That is a question about inventory, monitoring and response capability, and it shapes what you buy and from whom.

How it works

Discovery. Someone finds a flaw. It may be a security researcher who reports it privately to the vendor, the vendor’s own team, or an attacker who keeps it secret to use or sell.

Exploitation. If attackers have a working exploit before a fix exists, they can use it against targets. Some zero-days are used quietly against a few chosen victims; others are used widely once discovered, especially against internet-facing devices that are easy to find.

Disclosure and mitigation. When the vendor learns of the flaw, it usually publishes an advisory, often with interim mitigations such as configuration changes or disabling a feature, and works on a patch. Government agencies and threat intelligence sources may publish indicators of compromise to help defenders check whether they were hit.

Patch and catch-up. Once a fix is released, the zero-day window closes, although the flaw may still be described as a (former) zero-day. Many systems stay unpatched for weeks or months. Attackers often reverse-engineer patches to build exploits, so the period right after release can be the riskiest for slow patchers.

When it matters for buyers

  • When a peer gets hacked. Many high-profile incidents start with a zero-day in a widely used product; the first question is whether you run it too.
  • When choosing internet-facing products. A vendor’s track record on disclosure, patch speed and clear guidance matters as much as features.
  • When evaluating detection. Endpoint detection and response (EDR) and services such as managed detection and response (MDR) look for attacker behavior, which can catch activity that signature tools miss.
  • When building an asset inventory. You cannot react to an advisory quickly if you do not know which versions you run; attack surface management (ASM) helps on the internet-facing side.
  • When setting patch SLAs. Emergency patch processes for critical, actively exploited flaws should be faster than routine monthly cycles.

Questions to ask vendors

  • How do you notify customers of critical vulnerabilities in your product, and how fast?
  • What is your typical time from disclosure to patch for critical flaws, and do you publish interim mitigations?
  • For a managed security or MDR provider: how do you check our environment when a new zero-day is announced?
  • Do you hunt for indicators of compromise across our systems after a major disclosure?
  • For a patching service: what is your process and timeline for emergency out-of-cycle patches?
  • Can you tell us within hours which of our assets run an affected product and version?

How it differs from a known vulnerability

A known vulnerability, often tracked with a public Common Vulnerabilities and Exposures (CVE) identifier, has been disclosed and usually has a fix or workaround available. Routine vulnerability management finds and fixes these. A zero-day has no fix when attackers start using it, so defense depends on reducing exposure and detecting suspicious behavior until a patch arrives. For help building both capabilities, see our vulnerability management overview.

Frequently Asked Questions

What is the difference between a zero-day vulnerability and a zero-day exploit?
The vulnerability is the flaw itself. The exploit is the code or technique that takes advantage of it. A zero-day attack is the use of that exploit against real targets before a fix is available.
Can antivirus stop zero-day attacks?
Signature-based antivirus looks for known threats, so it can miss a new exploit. Behavior-based tools such as EDR look for suspicious activity, like an application suddenly launching a command shell, and can catch some zero-day attacks. No single tool reliably stops all of them, which is why layered defenses matter.
Is a vulnerability still a zero-day once a patch is out?
Usage varies. The zero-day window ends once a fix is available, and the flaw is then usually treated as a known vulnerability, though people may still call it a zero-day or a former zero-day. In practice the risk often rises after disclosure, because more attackers learn about the flaw while many organizations have not yet patched. Fast patching after release matters as much as defending before it.
What should we do when a zero-day affecting our systems is announced?
Confirm whether you run the affected product and version, apply the vendor's interim mitigations or workarounds, limit internet exposure of the affected system if you can, watch for signs of compromise, and patch as soon as a fix is released. If the system was exposed, consider whether it may already have been compromised.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.