← All terms

Zero-Day

A zero-day is a vulnerability unknown to the software vendor, exploitable before any patch exists — the vendor has had zero days to fix it.

A zero-day is a software vulnerability that is unknown to the vendor responsible for fixing it. The name refers to the defender's position: the vendor has had zero days to develop a patch, so at the moment of exploitation no fix exists and signature-based defenses have nothing to match against. The term is used loosely for three related things — the flaw itself (zero-day vulnerability), the code that abuses it (zero-day exploit), and an intrusion carried out with it (zero-day attack).

How it works

A researcher or attacker discovers a flaw before the vendor does. What happens next depends on who found it: legitimate researchers disclose it privately so a patch can ship, while attackers either use it directly or sell it — working exploits for widely deployed software command six- and seven-figure prices in private markets. Because no patch or detection signature exists, a zero-day exploit passes through defenses that rely on known indicators, which is why zero-days feature in high-end espionage and in mass-exploitation events where a single flaw in a popular product — a file-transfer appliance, a VPN gateway, a browser — is used against thousands of organizations at once. Once the vendor learns of the flaw, the clock flips: a patch is released, the exploit becomes an "n-day," and the race shifts to whether organizations patch faster than attackers scan.

How to defend against it

By definition you cannot patch a zero-day in advance, so defense means limiting what an unknown exploit can reach: prompt patching to close the n-day window, network segmentation and least privilege to contain a foothold, behavior-based endpoint detection that flags what exploit code does rather than what it looks like, and vendor-risk scrutiny for the internet-facing products most often targeted. Perspective matters too: zero-days are scarce, expensive and newsworthy, but the overwhelming majority of breaches begin with the human element — phishing, stolen credentials and manipulation, as the social engineering statistics show year after year. An organization worried about zero-days while untrained employees reuse passwords has the priorities inverted; measured security awareness closes the door attackers actually use.

Related terms

Attack VectorAn attack vector is the specific path an attacker uses to get in — an exploit, a stolen password, or, most often, a message aimed at a person.Supply Chain AttackA supply chain attack compromises a trusted vendor, software update, or service provider to reach that supplier's customers — trust as the attack vector.RansomwareRansomware is malware that encrypts or steals an organization's data and demands payment, most often delivered through phishing and stolen credentials.Penetration TestingPenetration testing is an authorized simulated attack that finds exploitable weaknesses — in systems, and increasingly in people and processes.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo