Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A zero-day is a software, hardware, or firmware vulnerability that is unknown or has no official fix available when it is discovered or exploited. A zero-day attack is an attack that takes advantage of a previously unknown vulnerability. The terms describe related but different things: the weakness, the method used against it, and the harmful activity.

What does “zero-day” mean?

There is no single wording used in every security reference. NIST defines a zero-day attack as “an attack that exploits a previously unknown hardware, firmware, or software vulnerability.” The definition appears in the NIST CSRC glossary, which cites CNSSI 4009-2022 and NISTIR 8011 Vol. 3.

Microsoft Learn uses patch availability to define a zero-day vulnerability: a software flaw for which no official patch or security update is available yet. The publisher may know about the flaw, or may not; public details about the risk may also be unavailable. Microsoft says these flaws are often actively exploited, not that exploitation is required for every flaw to qualify. See Microsoft’s zero-day mitigation guidance, last updated December 1, 2025.

In practice, people may use “zero-day” for the vulnerability, an exploit, or an attack. The precise meaning depends on context, so it helps to name which one you mean.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How are a vulnerability, exploit, and attack different?

  • Vulnerability: A weakness in software, hardware, firmware, a process, or a security control that a threat source could exploit or trigger. NIST’s general definition is in its vulnerability glossary.
  • Exploit: Code or a technique that takes advantage of a vulnerability.
  • Attack: The harmful activity that uses an exploit or otherwise takes advantage of the weakness.

Microsoft’s MSRC glossary describes a zero-day vulnerability as a flaw in software, hardware, or firmware unknown to its vendor or developer. These definitions emphasize different aspects: whether the vendor knows about the flaw, whether a fix is available, or whether an attack is exploiting it.

Why is it called a zero-day?

The name signals that defenders may have had no time with an available fix: the vulnerability is unknown, or there has been no official patch or security update to apply. It does not mean the flaw was discovered exactly zero days ago, nor does it mean every such flaw is already under attack.

What can a zero-day attack look like?

A historical U.S. government report describes an Internet Explorer scenario in which exploit code placed on certain websites could direct visitors to servers hosting an exploit and prompt the download of a malware-containing file or add-on. In simplified form, that report’s example was:

  1. A visitor opens a compromised or malicious webpage in a vulnerable browser.
  2. The page delivers or directs the browser to exploit code.
  3. The exploit may lead to a malware download.

This is a historical illustration, not evidence of a current Internet Explorer campaign or a universal attack path. The report is titled Zero-Day Vulnerabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you respond to a zero-day?

There is no single product or control that can guarantee protection from every zero-day. For organizations, the practical response is to reduce exposure, contain risk where appropriate, and apply the official update once it is available.

1. Check the affected vendor’s advisory and apply its mitigation

Identify the affected product and consult the vendor’s current security advisory. Follow its workaround or mitigation instructions while a patch is unavailable; Microsoft notes that workarounds may reduce risk until an update can be deployed. Avoid substituting generic advice for instructions specific to the affected software and environment.

2. Limit exposure if the risk warrants it

For an organization, temporarily isolating an affected system can be an emergency alternative when patching is not yet possible. Network segmentation, isolation, software-defined perimeters, and proxies are among the techniques listed in NIST’s security measures for EO-critical software use. Their suitability depends on the system and threat model; isolation can also disrupt normal operations.

NIST’s SP 1800-31 enterprise patching guide covers patching and inventory capabilities for routine and emergency situations, including isolation methods as emergency alternatives to patching.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Find every affected system

Maintain an inventory of software and systems so you can determine where a vendor’s mitigation applies and which machines need an update. Without that visibility, an organization may miss affected devices even when it has a response plan.

4. Install the official security update when released

Once the vendor publishes a security update, follow its installation instructions and your organization’s change process. Microsoft’s guidance shifts to updating the software after a patch is released; its vulnerability-management product also removes the zero-day tag at that point.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What zero-day protection can and cannot promise

Workarounds, isolation, segmentation, inventory, and prompt patching can reduce exposure or help contain an incident. They do not establish that any one antivirus product, VPN, router, or other single tool stops all zero-days. The right response depends on the affected system, the vendor’s available guidance, and the organization’s ability to reduce access or isolate the system safely.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.