The label indicates an absence of remediation lead time at that point. It describes the state of knowledge and remediation, not severity or proof that the weakness has been used in an attack.
Usage varies after disclosure. Some reports retain “zero-day” until a correction is available, but an unpatched vulnerability is not a zero-day merely because it lacks a patch. Reports should state when and by whom the weakness was known, whether exploitation was observed, and which mitigations or corrections were available.
Key points
Changing stateA privately discovered weakness may enter coordinated disclosure, receive an identifier, become public, and later be corrected. Its operational label can change during that sequence.
AssessmentConfirm affected products and configurations, evidence quality, exposure, privileges or interaction required, credible exploitation, and potential consequences instead of prioritizing on the label alone.
ResponseFollow supplier and coordinator guidance, reduce exposed paths, increase relevant monitoring, apply tested temporary mitigations, and deploy a validated correction when available.
Important limitationThe absence of a public Common Vulnerabilities and Exposures identifier or patch does not prove that a weakness is a zero-day, and a zero-day claim does not prove active exploitation, broad reachability, or critical impact.