In plain English
A zero-day is a security flaw that the software maker doesn't know about yet — so there's no patch available. Attackers who discover or buy zero-days have a window to exploit them freely until the vendor becomes aware and releases a fix. This is why rapid patch deployment (an Essential Eight control) is so critical once patches do become available.
