A zero-day vulnerability is a security flaw in software, firmware or hardware that attackers know about, or can use, before the vendor has released a fix. The name comes from the defender’s position: the vendor and its customers have had “zero days” to prepare a patch. Zero-days are prized by attackers because standard defenses such as patching and signature-based antivirus are not yet ready for them.
At a glance
- A zero-day is a flaw with no available fix at the time attackers start using it or it becomes public.
- The vulnerability is the flaw; the exploit is the code that uses it; a zero-day attack is the exploit used against real targets.
- Patching cannot help until a fix exists, so defense relies on mitigations, limiting exposure and detecting suspicious behavior.
- Internet-facing systems such as VPN appliances, firewalls, email servers and file-transfer tools are frequent targets.
- Once a patch ships, the race shifts to how quickly you can apply it.
What problem it solves
A zero-day is a problem, not a solution, but understanding the term helps buyers plan for one of the hardest situations in security. Most security programs are built around known weaknesses: scanners find missing patches, and patch management applies them. A zero-day breaks that cycle, because there is nothing to scan for and nothing to install yet.
For mid-sized organizations, the practical question is not whether they can prevent every zero-day, which no one can, but how quickly they can find out they are affected, reduce exposure and detect an intruder who got in through one. That is a question about inventory, monitoring and response capability, and it shapes what you buy and from whom.
How it works
Discovery. Someone finds a flaw. It may be a security researcher who reports it privately to the vendor, the vendor’s own team, or an attacker who keeps it secret to use or sell.
Exploitation. If attackers have a working exploit before a fix exists, they can use it against targets. Some zero-days are used quietly against a few chosen victims; others are used widely once discovered, especially against internet-facing devices that are easy to find.
Disclosure and mitigation. When the vendor learns of the flaw, it usually publishes an advisory, often with interim mitigations such as configuration changes or disabling a feature, and works on a patch. Government agencies and threat intelligence sources may publish indicators of compromise to help defenders check whether they were hit.
Patch and catch-up. Once a fix is released, the zero-day window closes, although the flaw may still be described as a (former) zero-day. Many systems stay unpatched for weeks or months. Attackers often reverse-engineer patches to build exploits, so the period right after release can be the riskiest for slow patchers.
When it matters for buyers
- When a peer gets hacked. Many high-profile incidents start with a zero-day in a widely used product; the first question is whether you run it too.
- When choosing internet-facing products. A vendor’s track record on disclosure, patch speed and clear guidance matters as much as features.
- When evaluating detection. Endpoint detection and response (EDR) and services such as managed detection and response (MDR) look for attacker behavior, which can catch activity that signature tools miss.
- When building an asset inventory. You cannot react to an advisory quickly if you do not know which versions you run; attack surface management (ASM) helps on the internet-facing side.
- When setting patch SLAs. Emergency patch processes for critical, actively exploited flaws should be faster than routine monthly cycles.
Questions to ask vendors
- How do you notify customers of critical vulnerabilities in your product, and how fast?
- What is your typical time from disclosure to patch for critical flaws, and do you publish interim mitigations?
- For a managed security or MDR provider: how do you check our environment when a new zero-day is announced?
- Do you hunt for indicators of compromise across our systems after a major disclosure?
- For a patching service: what is your process and timeline for emergency out-of-cycle patches?
- Can you tell us within hours which of our assets run an affected product and version?
How it differs from a known vulnerability
A known vulnerability, often tracked with a public Common Vulnerabilities and Exposures (CVE) identifier, has been disclosed and usually has a fix or workaround available. Routine vulnerability management finds and fixes these. A zero-day has no fix when attackers start using it, so defense depends on reducing exposure and detecting suspicious behavior until a patch arrives. For help building both capabilities, see our vulnerability management overview.
