GlossaryAttack surface and pentesting

Zero day

Short answer

A zero day is a vulnerability that attackers know about or exploit before the vendor has released a fix, so defenders have had zero days to patch it. Attacks that use it are called zero day exploits and are hard to stop with patching alone.

From zero day to known vulnerability

Once a vendor discloses the flaw and publishes a patch, it receives a CVE identifier and is no longer a zero day. The risk does not disappear: attackers start scanning the internet for systems that have not applied the patch yet, often within hours.

Why they matter for companies

Zero days in widely used products, such as VPN gateways, firewalls, file transfer tools and email servers, have been behind some of the largest attacks of recent years. Systems exposed to the internet are the most at risk, which is why knowing your attack surface matters: you cannot react to a new advisory for a product you do not know you are running. Our article on what your company exposes online explains how to find out.

How to reduce the impact

Since there is no patch at first, protection relies on other layers: keeping exposure to a minimum, segmenting networks, applying the vendor's temporary mitigations and detecting unusual behaviour with tools like EDR. When the patch arrives, apply it quickly. The CISA KEV catalogue lists vulnerabilities known to be exploited in the wild and helps decide what to patch first.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub