Zero-Day Vulnerability
A zero-day vulnerability is a security flaw unknown to the vendor at the time of exploitation, giving defenders no available patch or public defensive guidance when attacks occur, so exploitation typically precedes coordinated response.
What "Zero-Day" Actually Means
The term describes the state of vendor and defender awareness rather than a specific type of vulnerability. A zero-day is any vulnerability where attackers are exploiting the flaw before the vendor has released a fix (and often before the flaw is publicly known). Once the vulnerability is disclosed and patched, it is no longer a zero-day, though unpatched systems remain exposed.
Why Zero-Days Are a Distinct Risk Category
Standard vulnerability management processes assume defensive information exists: known vulnerabilities are cataloged in the CVE system, mitigations are documented, and patches are available. Zero-days violate all three assumptions. The defensive posture depends on general resilience rather than specific mitigations.
This is why response programs typically emphasize defense-in-depth rather than single-layer defenses. A zero-day that bypasses one control tier may still be caught by another, but a program dependent on a single defensive layer against known threats collapses when the layer is bypassed by an unknown threat.
Zero-Days in Quantified Programs
Quantified programs model zero-day risk as one component of overall scenario frequency. Historic loss data captures both known-vulnerability exploitation and zero-day exploitation without necessarily distinguishing between them at the scenario level. Detection speed, response effectiveness, and general resilience matter more against zero-days than specific patching cadence.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


