Zero-day vulnerability: what it is and how to stop it
A zero-day vulnerability is a flaw that no one has fixed yet, not because it's obscure, but because the vendor has had zero days to build a patch before someone starts exploiting it. That's the idea behind the name: the clock only starts once an attacker, or a security researcher, finds the weakness, and until a fix ships, every organization running the affected software is exposed.
These vulnerabilities exist in operating systems, applications, firmware and network devices, and they can sit undiscovered for months or years before anyone notices them. Once a threat actor exploits one, they can gain unauthorized access to a network, steal data or disrupt services, often well before the vendor or the wider security industry knows the flaw exists.
This guide covers the difference between a zero-day vulnerability, exploit and attack, how common they've become, and what actually reduces exposure, including where detection-based tools fall short and where prevention through Content Disarm and Reconstruction (CDR) changes the picture.
What is a zero-day vulnerability, exploit and attack?
The three terms get used interchangeably, but they describe different stages of the same problem.
Zero-day vulnerability: an unknown flaw in software, hardware or firmware that hasn't been patched, and that the vendor may not even know about yet.
Zero-day exploit: the specific method or code an attacker uses to take advantage of that vulnerability before a fix is available.
Zero-day attack: the real-world incident where an exploit is used against a target, such as a company network, a government system or an individual device.
In short: the vulnerability is the weakness, the exploit is the tool and the attack is what happens when someone uses it.
How common are zero-day vulnerabilities?
Zero-day exploitation isn't rare, and it isn't slowing down.
Google's Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in the wild in 2025. Of those, 43 (48%) targeted enterprise software and appliances, up from 36 (46%) in 2024, a sign that attackers are increasingly aiming at the infrastructure businesses run internally rather than consumer devices.
The window to react keeps shrinking, too. Mandiant's analysis of 112 vulnerabilities disclosed in 2024 found an average time-to-exploit of -1 day, meaning attackers were, on average, already exploiting the flaw before it was publicly disclosed. Verizon's 2025 Data Breach Investigations Report found that exploitation of vulnerabilities as an initial access vector grew 34% year-over-year, now accounting for 20% of breaches.
CrowdStrike's 2026 Global Threat Report points to the same trend: zero-day vulnerabilities exploited prior to public disclosure rose 42% in 2025. Zoom out further and the scale becomes clear: IBM X-Force has recorded 7,327 zero-day vulnerabilities since 1988, about 3% of all vulnerabilities on record.
Rapid7's 2026 Global Threat Landscape Report adds another data point on how fast this window is closing.
For CVSS 7-10 vulnerabilities published and added to CISA's Known Exploited Vulnerabilities (KEV) catalog in the same year, the median time from publication to KEV inclusion dropped from 8.5 days in 2024 to 5.0 days in 2025, and the mean fell from 61.0 days to 28.5 days. Confirmed in-the-wild exploitation of newly disclosed CVSS 7-10 vulnerabilities rose 105% year-over-year, from 71 cases in 2024 to 146 in 2025, even as total CVSS 7-10 disclosures grew far more slowly, from roughly 16,200 to 18,100 over the same period.
Rapid7 frames AI as an acceleration layer in this shift: it speeds up existing attacker playbooks, like phishing, scripting and iterative exploitation, rather than introducing fundamentally new attack techniques.
Patching after disclosure isn't fast enough to close this gap on its own.
How are they discovered?
Zero-day vulnerabilities surface in a few distinct ways.
Security researchers find many of them through routine software testing, code audits or, occasionally, by accident while investigating something unrelated. Vendors also run bug bounty programs that pay researchers to report flaws before anyone can exploit them.
Threat actors discover them too, sometimes independently and sometimes by buying access on underground markets. When a criminal or state-sponsored group finds one first, they tend to move fast: the value of a zero-day drops the moment it becomes public, so there's a strong incentive to exploit it quickly and quietly.
Recent zero-day attacks and vulnerabilities
Some zero-day attacks become well known because of how widely they spread or how much damage they caused.
Heartbleed (2014): a flaw in the OpenSSL cryptographic library let attackers read memory that should have stayed private, exposing passwords and encryption keys across a large share of the internet's web servers.
Petya and NotPetya (2017): originally packaged as ransomware, these attacks used a stolen exploit to spread rapidly through networks, wiping data rather than genuinely enabling recovery for a ransom.
WannaCry (2017): built on the leaked EternalBlue exploit targeting a flaw in Windows SMB, WannaCry infected an estimated 200,000 to 300,000 devices worldwide, disrupting the NHS, Honda and FedEx.
MOVEit (2023): attackers exploited a SQL injection flaw in Progress Software's MOVEit Transfer tool to steal data from thousands of organizations, including the BBC, British Airways and Boots.
PAN-OS GlobalProtect, CVE-2024-3400 (2024): a command injection flaw in Palo Alto Networks' firewall software was exploited by a suspected state-sponsored actor for weeks before a patch shipped. There's no public dollar estimate of the damage, but it's a clear sign that zero-day exploitation of enterprise security appliances didn't stop in 2023.
The zero-day exploit lifecycle: from discovery to patch
Security teams sometimes describe the zero-day cycle with a bit of dark humor: Patch Tuesday, Exploit Wednesday, Uninstall Thursday. It's a joke, but it points at something real.
Microsoft and many other vendors release patches on a fixed schedule, often the second Tuesday of the month ("Patch Tuesday"). Attackers know this schedule too, and they reverse-engineer new patches almost immediately to find the vulnerability being fixed and build an exploit for anyone who hasn't updated yet ("Exploit Wednesday"). Organizations that can't test and roll out a patch fast enough are left exposed, and in some cases have to pull a system offline until they can apply the fix safely ("Uninstall Thursday").
File-based delivery makes this worse. Around two-thirds of malware is still delivered through PDFs and other document attachments in email, precisely the kind of file people open every day without a second thought. A patch fixes the underlying vulnerability, but it does nothing to stop a malicious file from reaching someone's inbox in the meantime.
This lifecycle is why patching alone, even fast patching, can't fully close the zero-day gap. The exposure window exists by definition between when a vulnerability is found and when every affected system is updated.
Why detection-based security fails against zero-day threats
Most protection strategies combine several layers: patch management to close known vulnerabilities quickly, vulnerability management to track and prioritize exposure across an estate, attack surface management to reduce what's exposed in the first place, threat intelligence feeds to flag emerging risks, anomaly detection to spot unusual behavior.
Each of these plays a role. None of them, alone, closes the zero-day gap, because most detection-based approaches share the same underlying assumption: something needs to be recognized as bad before it gets blocked.
Traditional antivirus and firewall tools rely on known signatures or behavioral rules. If a threat hasn't been seen before, and a zero-day exploit by definition hasn't, there's nothing to match against.
Sandbox solutions run suspicious files in an isolated environment to observe what they do before releasing them. Attackers know this, and some malware is built to detect a sandbox and stay dormant until it reaches a real environment, defeating the purpose of the test.
Machine learning and AI-based detection improve on static signatures by looking for patterns associated with malicious behavior. That's useful, but it's still reactive at its foundation: the model has to have learned that a pattern is risky, which means novel zero-day techniques can slip through until enough examples exist to train against.
The common thread: every one of these approaches tries to catch a threat after it has already reached the environment. For zero-day vulnerabilities specifically, where there's no signature, no known pattern and no advance warning, detection alone leaves a gap.
How Glasswall CDR closes the zero-day gap
Glasswall's Content Disarm and Reconstruction (CDR) technology approaches the problem differently: instead of trying to recognize a threat, it treats every file as untrusted by default, rebuilds it against the manufacturer's known-good specification and removes anything that doesn't belong, before the file reaches a user. That means protection doesn't depend on having seen a threat before, which is exactly where zero-day exploits do the most damage. For a closer look at how the rebuild process works, see what is Content Disarm and Reconstruction (CDR)?
Zero-day vulnerabilities aren't going away, and the data above shows they're accelerating. Reducing exposure means shifting some of the burden away from detection and toward prevention, before execution rather than after infection.
A zero-day vulnerability is a flaw in software, hardware or firmware that the vendor hasn't patched yet, often because they don't know it exists. The name comes from the vendor having zero days of advance warning before it can be exploited.
What is the difference between a zero-day vulnerability and a zero-day exploit?
The vulnerability is the underlying weakness itself. The exploit is the specific code or technique an attacker uses to take advantage of that weakness. A vulnerability can exist for years without anyone developing an exploit for it.
How are zero-day vulnerabilities discovered?
Security researchers find many through testing, code audits or bug bounty programs. Threat actors also discover them independently, or buy access to them, and tend to exploit them quickly and quietly before the flaw becomes public.
Can antivirus software detect zero-day attacks?
Not reliably. Traditional antivirus relies on known signatures, and a zero-day exploit by definition hasn't been seen before, so there's nothing for it to match against. Behavioral and AI-based tools improve on this but still depend on recognizing a pattern, which limits how early they can catch a genuinely new threat.
How can organizations protect against zero-day vulnerabilities?
No single control closes the gap. Patch management, vulnerability management, attack surface management, threat intelligence and Zero Trust architecture all reduce exposure, and prevention-focused approaches like Content Disarm and Reconstruction (CDR) remove the risk from files before they're opened, rather than trying to detect it afterward.
What are some recent examples of zero-day attacks?
MOVEit (2023), WannaCry and Petya/NotPetya (both 2017), and Heartbleed (2014) remain some of the most significant. A 2024 example is CVE-2024-3400, a command injection flaw in Palo Alto Networks' PAN-OS GlobalProtect gateway that was exploited before a patch was available.
Jake Bussell
Glasswall's Marketing Director, Jake, drives strategies that empower the company's sales teams. A highly creative and seasoned industry professional, his passion for branding and customer-focused messaging fuels growth across domestic and international markets.
See what Zero Trust file protection looks like. Live, in 25 minutes.
A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.
What's in the demo
See malicious files rebuilt in real time Watch Glasswall remove hidden threats and return a safe, usable files.
Integrate security without disruption See how Glasswall fits into your existing workflows and infrastructure.
Gain complete visibility into file risk Uncover threats, anomalies and hidden file intelligence.
“
Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.