Glossary

Zero-day vulnerability

A software flaw unknown to the vendor, or unpatched, at the time it is discovered or actively exploited.

Also called: zero-day, 0-day

A zero-day vulnerability is a software flaw that is unknown to the vendor, or known but not yet patched, at the time it is discovered or actively exploited, meaning defenders have had zero days to prepare a fix before exposure. An attack that uses such a flaw before a patch exists is a zero-day exploit; the terms are often used interchangeably but describe the flaw and the attack respectively.

Zero-days differ from ordinary vulnerabilities mainly in timing risk: once a vendor issues a patch and it becomes public knowledge, the flaw is no longer a zero-day even if many systems remain unpatched, a separate and much more common risk called an n-day vulnerability. Because no signature or patch exists yet, zero-day exploitation is one of the scenarios user and entity behavior analytics and behavior-based endpoint detection and response are specifically designed to catch, since indicator-based detection has nothing to match against.

Zero-days matter disproportionately in threat intelligence because they are expensive and scarce, so their use often signals a well-resourced attacker. A common misreading is assuming any newly disclosed vulnerability is a zero-day; the term applies only when exploitation predates a public fix, not simply to freshly announced flaws.

Last reviewed September 22, 2026

In the index now

Related terms