# What is a Zero-Day Vulnerability?

> A zero-day vulnerability is a security weakness unknown to the affected technology’s supplier or maintainer when it is first disclosed or exploited, typically before a practical correction is available.

- Canonical URL: https://yellowcube.eu/glossary/zero-day-vulnerability/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The label indicates an absence of remediation lead time at that point. It describes the state of knowledge and remediation, not severity or proof that the weakness has been used in an attack.

Usage varies after disclosure. Some reports retain “zero-day” until a correction is available, but an unpatched vulnerability is not a zero-day merely because it lacks a patch. Reports should state when and by whom the weakness was known, whether exploitation was observed, and which mitigations or corrections were available.

### Key points

- **Changing state:** A privately discovered weakness may enter coordinated disclosure, receive an identifier, become public, and later be corrected. Its operational label can change during that sequence.
- **Assessment:** Confirm affected products and configurations, evidence quality, exposure, privileges or interaction required, credible exploitation, and potential consequences instead of prioritizing on the label alone.
- **Response:** Follow supplier and coordinator guidance, reduce exposed paths, increase relevant monitoring, apply tested temporary mitigations, and deploy a validated correction when available.
- **Important limitation:** The absence of a public Common Vulnerabilities and Exposures identifier or patch does not prove that a weakness is a zero-day, and a zero-day claim does not prove active exploitation, broad reachability, or critical impact.

### Related terms

[Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Exploit](<https://yellowcube.eu/glossary/exploit/>) · [Coordinated vulnerability disclosure (CVD)](<https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/>) · [Common Vulnerabilities and Exposures (CVE)](<https://yellowcube.eu/glossary/common-vulnerabilities-and-exposures/>) · [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/>)

### Sources

[NIST CSRC Glossary: Zero Day Attack](https://csrc.nist.gov/glossary/term/zero_day_attack) · [NIST SP 800-216: Recommendations for Federal Vulnerability Disclosure Guidelines](https://csrc.nist.gov/pubs/sp/800/216/final) · [CISA: Guide to Vulnerability Reporting for America’s Election Administrators](https://www.cisa.gov/sites/default/files/publications/guide-vulnerability-reporting-americas-election-admins_508.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

