Zero day
A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched.
A zero day is a security vulnerability unknown to the vendor with no patch available. The term also covers the exploit or attack that uses such a flaw before defenders can fix it.
What it is
In cybersecurity, a zero-day vulnerability is a flaw in software, hardware, or firmware that the vendor hasn't discovered or patched yet. A zero-day exploit is the code or method used to take advantage of that flaw, and a zero-day attack is when that exploit is deployed before any fix exists.
Why it matters
Zero-day flaws are high-risk because they can enable unauthorized access, malware delivery, or data theft without detection by standard signature-based defences. Since defenders have had zero days to prepare, these vulnerabilities can be exploited quietly until discovered and mitigated.
Key details
Defence relies on behaviour-based detection, network monitoring, and layered controls rather than signatures alone. Rapid patching once fixes are released is critical. In Canada, zero-day threats are treated as high-priority for individuals, businesses, and government systems.
In short
- A zero-day vulnerability is unknown to the vendor and has no patch.
- Zero-day exploits and attacks use that flaw before a fix exists.
- They are difficult to block with traditional defences.
- Canadian cybersecurity guidance emphasizes layered defences and fast patching.
Zero-day vulnerabilities affect Canadian individuals, businesses, government systems, and critical infrastructure, and Canadian cybersecurity guidance commonly treats them as high-priority threats requiring layered defences and rapid patching when fixes become available.
Quick questions
What is a zero-day vulnerability?
Why is it called a zero day?
Can zero-day flaws affect hardware?
Sources
- Wikipedia — https://en.wikipedia.org/wiki/Zero-day_vulnerabilitySupports: Basic definition of zero-day vulnerability, exploit, and attack
- RAND — https://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdfSupports: Meaning of zero-day vulnerabilities and the term’s reference to days known to the vendor
- CrowdStrike — https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/zero-day-exploit/Supports: Distinction between vulnerability, exploit, and attack
- Splunk — https://www.splunk.com/en_us/blog/learn/zero-day.htmlSupports: Unknown vulnerabilities, lack of patches/signatures, and defence considerations
- SentinelOne — https://www.sentinelone.com/cybersecurity-101/threat-intelligence/zero-day-vulnerabilities-attacks/Supports: Attacks before patches and common impacts
- HPE — https://www.hpe.com/us/en/what-is/zero-day-vulnerability.htmlSupports: Definition of zero-day vulnerability and lack of patch
- Tenable — https://www.tenable.com/cybersecurity-guide/principles/zero-day-vulnerabilitySupports: Known vulnerability without a patch and the 'zero days' concept
- Orca Security — https://www.orca.security/glossary/zero-day-vulnerability/Supports: Zero-day applicability to software, hardware, and firmware