Skip to main content
Cybersecurity

Zero-Day Exploit

An attack that exploits a previously unknown software vulnerability before the vendor has released a patch, leaving systems temporarily defenseless.

A zero-day exploit targets a software vulnerability that is unknown to the vendor and for which no patch exists. “Zero-day” refers to the number of days the vendor has had to address the flaw: zero. These exploits are extremely valuable on both legitimate (bug bounty) and black markets.

Zero-day exploits are particularly dangerous because traditional signature-based defenses cannot detect unknown attacks. They’re used in both targeted attacks (nation-state espionage) and widespread campaigns (browser and OS vulnerabilities).

While individual users can’t prevent zero-day exploits, layered defenses minimize their impact: keeping software updated (patches are released quickly once discovered), using network segmentation, implementing behavioral detection, and maintaining strong credential hygiene so that even if initial access is gained through a zero-day, lateral movement is limited.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide