Zero-Day Vulnerability
Pronunciation: ZEER-oh DAY vul-nuh-ruh-BIL-uh-tee
Definition
Zero-Day Vulnerability is a software or hardware vulnerability for which defenders do not yet have an effective broadly available fix or for which the affected organization had no prior remediation opportunity when exploitation began. The term may describe unknown flaws or newly disclosed flaws under active exploitation, so reports should state the specific meaning and timeline. It should be interpreted alongside Vulnerability Management, which may affect the same workflow without representing the same control, event, or risk.
Overview
Zero-Day Vulnerability is a software or hardware vulnerability for which defenders do not yet have an effective broadly available fix or for which the affected organization had no prior remediation opportunity when exploitation began. The term may describe unknown flaws or newly disclosed flaws under active exploitation, so reports should state the specific meaning and timeline. It should be interpreted alongside Vulnerability Management, which may affect the same workflow without representing the same control, event, or risk.
Attackers can exploit exposed systems before signatures, patches, detections, and operational guidance are mature, producing rapid compromise and uncertain scope.
Organizations should use layered controls, attack-surface reduction, behavior monitoring, isolation, least privilege, emergency change processes, threat intelligence, temporary mitigations, and rapid patch validation.
Retain affected product and versions, discovery and exploitation dates, indicators, exposure inventory, mitigations, vendor guidance, patch state, incident findings, and residual risk.
Assessment of Zero-Day Vulnerability should trace a software or hardware vulnerability for which defenders do not yet have an effective broadly available fix or for which the affected organization had no prior remediation opportunity when exploitation from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving software should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the Zero-Day weakness should be tested against the architecture associated with software.
Retesting for Zero-Day Vulnerability should reproduce the Zero-Day weakness involving software, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
Zero-Day Vulnerability is a software or hardware vulnerability for which defenders do not yet have an effective broadly available fix or for which the affected organization had no prior remediation opportunity when exploitation began.
Sources
- Known Exploited Vulnerabilities Catalog — CISA (2026-08-03)
- Vulnerability Management — NIST (2026-08-03)
- Common Vulnerabilities and Exposures — CVE Program (2026-08-03)