Zero-Day Vulnerability
A zero-day vulnerability is a security flaw in software, hardware, or firmware that its developers or defenders do not yet know about, meaning no fix or patch is available when it is discovered or exploited. Because the vendor has had no time to address it, attackers who find such a flaw can potentially use it to gain unauthorized access before defenders can respond. The name reflects that developers have had zero days to prepare a remedy.
A zero-day vulnerability is a previously unknown or unaddressed flaw in code, system design, software, hardware, or firmware that is not yet known to the developers or to parties capable of mitigating it, and for which no patch is available. Because remediation lags discovery, the flaw can be leveraged as an attack vector to gain unauthorized access, escalate privileges, or otherwise compromise a system prior to vendor mitigation. In practice, distinctions are often drawn between the underlying zero-day vulnerability, a zero-day exploit that weaponizes it, and a zero-day attack that uses that exploit against a target.
Why it matters
Zero-day vulnerabilities represent a distinct challenge because, by definition, no patch exists at the moment the flaw is discovered or exploited. Traditional vulnerability management relies on identifying known weaknesses and applying vendor-supplied fixes, but a zero-day removes that safety margin entirely: the developer has had zero days to prepare a remedy, and defenders may be unaware the flaw exists until it is used against them. This inverts the usual timeline of patch-then-protect and forces security leaders to think in terms of resilience, detection, and containment rather than remediation alone.
For organizations engaging a virtual CISO, the relevance is primarily one of governance and risk framing rather than hands-on hunting for unknown flaws. A vCISO typically helps a client understand that no security program can guarantee prevention of a zero-day exploit, and that the goal is to reduce exposure and limit impact through layered controls, timely patching once fixes become available, and incident readiness. It is a common mistake to assume that any single tool, provider, or leadership arrangement eliminates zero-day risk; experienced practitioners insist that this class of vulnerability be treated as an accepted residual risk that is managed, not solved.
The accountability distinction also matters here. A vCISO advises on strategy, prioritization, and program design, but legal and organizational accountability for security decisions, including how much residual zero-day risk an organization tolerates, generally remains with the client organization and its officers. The value of that advisory relationship depends heavily on organizational maturity, stakeholder cooperation, and whether detection and response capabilities are actually in place to catch exploitation that bypasses preventive controls.
Who it's relevant to
Inside 0-day
Common questions
Answers to the questions practitioners most commonly ask about 0-day.