Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Zero day

Knowledge hub

Zero day

A vulnerability exploited before any fix exists.

What it means

A zero day is a vulnerability under attack before a fix exists. The name counts the days the maker has had to respond: none. NIST describes the attack as one exploiting a previously unknown flaw.

People use the term loosely. Most of what people call a zero day is a recently published flaw with a patch nobody applied. That is a different problem entirely.

Why it matters

You cannot patch what has no patch, so prevention is the wrong frame. Ask instead how quickly you would find out, and how contained the damage would be.

That points your money somewhere more productive. Logs you can search, alerts somebody genuinely reads, and a design where one compromised component does not open everything else. Containment is the part you control. Detection speed is something you can improve. Perfect prevention is not. Assume one lands eventually, and ask what it would cost you on an ordinary Tuesday.

How it shows up

When one gets announced, the scramble runs the same way every time. Do we run this? In which release? Reachable from outside? Since when? Teams with an inventory answer in an hour. Teams without one spend two days finding out.

The far more common case deserves more of your attention: a flaw published months ago, patch available, still running because nobody owned the upgrade. CISA keeps a catalogue of the flaws attackers genuinely use, and plenty of the entries are old. Write your steps down before you need them, including who decides to take a service offline and who tells customers.

Questions people ask

Zero day, answered

What is the difference between a zero day and a CVE?

A zero day has no fix and usually no identifier, because the maker does not know about it yet. A CVE is a published identifier for a flaw somebody has disclosed.

A zero day stops being one the moment a patch and an identifier appear. After that it is a known flaw you have not applied.

Can you defend against something nobody knows about?

Not directly, and any vendor promising otherwise is overselling. What you can do is limit the blast radius and shorten the time to notice.

Separate privileges, keep searchable logs, and make sure one compromised component cannot reach the database, the build system and the secrets at once.

Was it really a zero day, or did we just not patch?

Worth asking every time, because the answer changes who owns the problem. If a patch existed on the day of the attack, it was not a zero day.

The label matters less than the honesty. Calling a missed upgrade a zero day hides the process failure that caused it.

Do zero days cause most breaches?

No. Investigated breaches overwhelmingly involve known flaws with patches available, stolen credentials and missing access checks.

Zero days get attention because they make better headlines. Your patch backlog is the more likely route in.

Should we buy a tool that promises zero-day protection?

Read carefully what it actually claims. Most of these products detect patterns of behaviour rather than specific flaws, which is genuinely useful but not the same as prevention.

Buy it for detection and containment if you need those. Do not let it push the patching backlog further down the list.

How fast would you find out?

Cyberlop will not predict the next one. It tells you which known classes your application is open to today, with proof attached. A pilot on one application is $199 for 30 days.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.