IronSights

Threats & attacks

Zero-day vulnerability

A software vulnerability that is unknown to the vendor or has no patch available, leaving systems exposed to exploitation with no vendor-supplied defence.

Also known aszero-day0-dayzero day exploit

In plain English

A zero-day is a security flaw that the software maker doesn't know about yet — so there's no patch available. Attackers who discover or buy zero-days have a window to exploit them freely until the vendor becomes aware and releases a fix. This is why rapid patch deployment (an Essential Eight control) is so critical once patches do become available.

Keep learning

More terms in the IronSights Glossary.