Definition · Known Vulnerabilities (CVEs)

What is Zero-Day?

A zero-day is a vulnerability for which no vendor patch exists at the time it becomes a problem — either because attackers found and used it first, or because details were published before a fix shipped. The name refers to the number of days defenders have had a patch: zero. Once an update is released, the same flaw is usually described as an n-day.

Zero-day vulnerability, exploit, and attack

Three related things share the label:

  1. Zero-day vulnerability — the underlying flaw in the software
  2. Zero-day exploit — the working exploit code that abuses it
  3. Zero-day attack — the use of that exploit against real targets

A vulnerability may be a zero-day for weeks before a CVE identifier is assigned and published, which is why the absence of a CVE in your inventory is not evidence that nothing is wrong.

Why zero-days matter for external exposure

Edge systems — VPN appliances, file transfer products, mail gateways, load balancers — are attractive zero-day targets precisely because they are reachable from the internet by design and often sit in front of internal networks. When a zero-day in one of these products becomes public, the first defensive question is factual rather than analytical: which of these do we actually run, on which hostnames, and are they exposed?

Responding without a patch

Until a fix exists, the available options are compensating ones: removing the service from public reachability, restricting source addresses, disabling the affected feature, applying vendor workarounds, and increasing monitoring on the host. An accurate asset discovery baseline shortens this work from days of searching to a single query.

Zero-days feed into the KEV catalogue once exploitation is confirmed, and their fixes then become ordinary patch management work. Reducing how much software is internet-facing in the first place is the structural mitigation — the aim of external attack surface management.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.