From zero day to known vulnerability
Once a vendor discloses the flaw and publishes a patch, it receives a CVE identifier and is no longer a zero day. The risk does not disappear: attackers start scanning the internet for systems that have not applied the patch yet, often within hours.
Why they matter for companies
Zero days in widely used products, such as VPN gateways, firewalls, file transfer tools and email servers, have been behind some of the largest attacks of recent years. Systems exposed to the internet are the most at risk, which is why knowing your attack surface matters: you cannot react to a new advisory for a product you do not know you are running. Our article on what your company exposes online explains how to find out.
How to reduce the impact
Since there is no patch at first, protection relies on other layers: keeping exposure to a minimum, segmenting networks, applying the vendor's temporary mitigations and detecting unusual behaviour with tools like EDR. When the patch arrives, apply it quickly. The CISA KEV catalogue lists vulnerabilities known to be exploited in the wild and helps decide what to patch first.




