What cybersecurity term describes a vulnerability unknown to the software maker before attackers or researchers discover it?

The story behind the answer

A zero-day vulnerability is a software weakness unknown to the maker before attackers or researchers discover it.

The phrase refers to the vendor having had zero days to prepare an official fix or defense. A zero-day exploit is the code or technique that takes advantage of that weakness; the vulnerability and the exploit are related but not identical terms.

A flaw can remain a zero-day only while the affected developer has not had an opportunity to address or publicly disclose it. Once a patch or detailed disclosure gives defenders time to respond, the term may no longer describe the vulnerability, even if many systems remain unpatched.

Zero-day does not automatically mean an attack is occurring. Researchers can discover flaws responsibly and notify the vendor before criminal exploitation. Conversely, a previously unknown flaw may be exploited in the wild before defenders understand how it works.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: