Back to glossary

Zero-day

2 min read

In vulnerability terms, a zero-day is a vulnerability being exploited before the vendor has a fix, so there is nothing to patch. Most real-world compromise is not this: it is n-day, a known vulnerability with a patch available that nobody applied. The distinction decides where a defence budget should go.

July 30, 2026
Compartir:

What it is

A zero-day threat is one that takes advantage of a security vulnerability for which the vendor has not yet published a fix. The vehicle is usually an exploit written specifically for that flaw.

How it works

The name refers to the number of days the vendor has had to respond, which is none. Three states are worth separating because the same phrase is used loosely for all of them. A vulnerability nobody knows about, which is a risk that cannot be managed. A vulnerability under exploitation with no fix available, which is the true zero-day and requires mitigation and detection rather than patching. And a vulnerability with a fix that the organisation has not deployed, which is an n-day and is a process problem.

Only the second is what the word should mean. The third is what compromises most organisations, and calling it a zero-day in an incident report moves the blame from the patch cycle to fate.

What goes wrong

Budget follows the wrong word. Preparing for the truly unknown is expensive and mostly means detection, segmentation and response capability. Closing the n-day window is comparatively cheap and is exactly what most estates have not done, which is why the mass exploitation events we see follow public disclosure rather than precede it: the window between a fix being published and it being deployed is measured in weeks or months, and exploitation frequently begins within days.

The second failure is the response to a disclosure with no fix, which is where the real definition applies. The correct actions are removing exposure, applying the vendor mitigation, hunting for evidence of exploitation on the assumption that it may already have happened, and raising logging on the affected component. Waiting is a decision, and it is usually the one taken.

Third, a zero-day is expensive to acquire and to burn, so it is used against targets worth that cost. Most organisations are compromised by an exploit for something patched last quarter, or by credentials bought from a broker, which needs no vulnerability at all.

Where this shows up in an audit

We do not use undisclosed exploits on client engagements, and it is worth being explicit about that, because a report should reflect what an ordinary determined attacker would do. What we do measure is the n-day window: how long a published fix takes to reach production on the estate we tested, which is a number the client can act on. The KEV catalogue is the shortest list of things to fix first, and the age of the oldest unpatched item on a reachable host is the figure that predicts the next incident. See also patch management.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.