Bryan McAllister’s personal reference notebook
September 11, 2026Short & citedBlog
Civic Viewpoint.
A quiet encyclopedia with a personal desk
How It Works • Cybersecurity

Zero day

A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched.

Updated September 11, 20261 min readCited sources

A zero day is a security vulnerability unknown to the vendor with no patch available. The term also covers the exploit or attack that uses such a flaw before defenders can fix it.

What it is

In cybersecurity, a zero-day vulnerability is a flaw in software, hardware, or firmware that the vendor hasn't discovered or patched yet. A zero-day exploit is the code or method used to take advantage of that flaw, and a zero-day attack is when that exploit is deployed before any fix exists.

Why it matters

Zero-day flaws are high-risk because they can enable unauthorized access, malware delivery, or data theft without detection by standard signature-based defences. Since defenders have had zero days to prepare, these vulnerabilities can be exploited quietly until discovered and mitigated.

Key details

Defence relies on behaviour-based detection, network monitoring, and layered controls rather than signatures alone. Rapid patching once fixes are released is critical. In Canada, zero-day threats are treated as high-priority for individuals, businesses, and government systems.

In short

  • A zero-day vulnerability is unknown to the vendor and has no patch.
  • Zero-day exploits and attacks use that flaw before a fix exists.
  • They are difficult to block with traditional defences.
  • Canadian cybersecurity guidance emphasizes layered defences and fast patching.
Canadian angle

Zero-day vulnerabilities affect Canadian individuals, businesses, government systems, and critical infrastructure, and Canadian cybersecurity guidance commonly treats them as high-priority threats requiring layered defences and rapid patching when fixes become available.

Quick questions

What is a zero-day vulnerability?
It is a security flaw unknown to the vendor or defenders with no available patch at the time it is discovered or exploited.
Why is it called a zero day?
Because defenders have had zero days to prepare or release a fix before the flaw is used against them.
Can zero-day flaws affect hardware?
Yes, zero-day vulnerabilities can occur in software, hardware, and firmware.

Sources

  1. Wikipediahttps://en.wikipedia.org/wiki/Zero-day_vulnerability
    Supports: Basic definition of zero-day vulnerability, exploit, and attack
  2. RANDhttps://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdf
    Supports: Meaning of zero-day vulnerabilities and the term’s reference to days known to the vendor
  3. CrowdStrikehttps://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/zero-day-exploit/
    Supports: Distinction between vulnerability, exploit, and attack
  4. Splunkhttps://www.splunk.com/en_us/blog/learn/zero-day.html
    Supports: Unknown vulnerabilities, lack of patches/signatures, and defence considerations
  5. SentinelOnehttps://www.sentinelone.com/cybersecurity-101/threat-intelligence/zero-day-vulnerabilities-attacks/
    Supports: Attacks before patches and common impacts
  6. HPEhttps://www.hpe.com/us/en/what-is/zero-day-vulnerability.html
    Supports: Definition of zero-day vulnerability and lack of patch
  7. Tenablehttps://www.tenable.com/cybersecurity-guide/principles/zero-day-vulnerability
    Supports: Known vulnerability without a patch and the 'zero days' concept
  8. Orca Securityhttps://www.orca.security/glossary/zero-day-vulnerability/
    Supports: Zero-day applicability to software, hardware, and firmware