A zero-day vulnerability is a security flaw that attackers can use before the software vendor even knows it exists. There is no patch ready, because nobody who could write one knows the flaw is there yet. Google’s own threat intelligence team tracked 90 zero-day vulnerabilities exploited in the wild across 2025, up from 78 the year before. Almost half of those were aimed squarely at enterprise technology, not consumer apps. That is the environment most UK businesses now operate in.

Here is what a zero-day vulnerability actually is, why it keeps showing up more often, and what changes for a business when the flaw it is dealing with has no fix waiting for it.
Table of Contents
What makes a vulnerability “zero-day”
Every piece of software ships with flaws nobody has found yet. Most get discovered by researchers. They get reported responsibly. They get patched before anyone outside the process notices. A flaw earns the “zero-day” label when someone starts exploiting it, or could exploit it, before the vendor has had any time, zero days, to fix it. That is what makes a zero-day vulnerability different from an ordinary bug.
Three related terms describe different stages of the same problem. Mixing them up leads to sloppy thinking about risk:
| Term | What it means |
|---|---|
| Zero-day vulnerability | The unpatched flaw itself |
| Zero-day exploit | Working code or a technique that triggers the flaw |
| Zero-day attack | The exploit being used against a real target |
A vulnerability can exist quietly for years before anyone builds an exploit for it. Once it turns up in live attacks, agencies such as CISA add it to their Known Exploited Vulnerabilities catalogue and push for urgent remediation, regardless of what its severity score says on paper.
The numbers behind the rise
The UK’s National Cyber Security Centre first flagged this shift in November 2024. It warned, alongside allied agencies, that attackers were increasingly favouring zero-days over vulnerabilities that already had a patch sitting unapplied. In 2023, most of the year’s top exploited flaws were used as zero-days from day one. In 2022, it was under half.
Google’s Threat Intelligence Group backed that up with hard numbers in its 2025 review. Attackers exploited 90 zero-day vulnerabilities across the year. Security and networking products alone accounted for 21 of them, roughly half of everything aimed at enterprises. Cisco, Fortinet, Ivanti and VMware each showed up repeatedly on the list. Browser zero-days, once the dominant category, made up under 10% of the total. That is a sharp drop from the 2021-2022 peak.
The takeaway for a business is blunt: the software sitting at your network edge, firewalls, VPN gateways, file transfer tools, is now a more common zero-day target than the browser your staff use every day.
Two cases that show what actually happens
In May 2023, the Cl0p ransomware group began exploiting a SQL injection flaw in Progress Software’s MOVEit Transfer, tracked as CVE-2023-34362, weeks before any patch existed. CISA’s advisory warned of widespread exploitation of unpatched, internet-facing servers. The breach eventually reached thousands of organisations through stolen file-transfer data, entirely because the flaw was exploited before defenders had any warning.
Closer to home, Aardwolf covered a recent SharePoint attack chain that chained multiple weaknesses to steal server keys before Microsoft’s fix landed. Both cases share the same lesson about a zero-day vulnerability: the initial flaw rarely does all the damage on its own. It is what an attacker reaches next that decides how bad the incident gets. That is also why a raw CVE number tells you so little by itself. Our guide to what a CVE actually is covers why severity and the identifier are separate questions.
Who is actually behind these attacks
Google’s 2025 breakdown gives a useful picture of who sits on the other end of a zero-day exploit. Commercial surveillance vendors build and sell spyware to governments. For the first time, they were attributed to more zero-day exploitation than any state-sponsored group. China-linked groups remained the most active state actors, tied to more than ten zero-days across the year. Financially motivated criminal groups accounted for nine. North Korean groups were not attributed to any zero-day exploitation in 2025, down from five the year before.
That spread matters for how a business thinks about risk. A zero-day vulnerability is not one type of threat with one motive behind it. It can just as easily be a ransomware crew after a payout as a state actor after espionage. The entry point they use often looks identical from a defender’s side.
Who finds zero-days first, and why it matters who
Independent researchers and bug bounty hunters report flaws through official channels, often for credit or a payout. The NCSC publishes a Vulnerability Disclosure Toolkit to help organisations set up somewhere for that kind of report to land. Penetration testers work through the exact configuration a business runs. They regularly surface the chained, context-specific weaknesses that a generic scanner misses.
On the other side, criminal groups, commercial surveillance vendors and state-linked actors look for the same flaws too. They use them quietly rather than report them. Whoever finds a given flaw first decides whether it becomes a patch or a headline.
What actually reduces your risk
You cannot patch a flaw nobody has disclosed. That is the nature of a zero-day vulnerability. What you can control is how much damage it does once an attacker is past the front door:
- Cut what is exposed to the internet. Fewer services means fewer places for an unknown flaw to live.
- Split up the network. One compromised system should not be able to reach everything else.
- Watch for odd behaviour, not just known signatures. A genuine zero-day will not match an existing rule.
- Keep an incident plan current and tested. Make sure the people who would run it know it well.
- Test often, and test more than known bugs. Check how your systems and staff hold up under real attack.
A penetration test will not predict the next zero-day vulnerability, no one can. But it consistently finds the weak chaining points and misconfigurations that turn a single flaw into a full breach once one does land. If you want a clear-eyed view of where that risk sits in your own environment, get in touch. We can talk through a scoped review.
Zero-day vulnerability FAQs
What’s the difference between a zero-day vulnerability and a zero-day exploit?
The vulnerability is the underlying flaw. The exploit is the working code or method that actually triggers it. A flaw can go undiscovered for years. Nobody may ever build an exploit for it at all.
Why are zero-day attacks increasing?
Many businesses have got faster at applying known patches. That closed the old window of opportunity. So attackers shifted toward flaws with no existing patch instead. Enterprise security and networking products have become a particular focus.
Does a high CVSS score mean a vulnerability is being exploited as a zero-day?
No. CVSS measures theoretical severity, not whether attackers are actively using the flaw. A moderate-scoring bug already under attack is more urgent than a critical-scoring one that is not.
Can a small UK business actually be hit by a zero-day vulnerability?
Yes. Most zero-days target widely used products: email platforms, VPNs, file transfer tools. Small and mid-sized businesses run this software just as much as large enterprises do. Being a smaller target does not mean using different software.
What is the first thing to do when a zero-day is announced?
Check the vendor’s advisory for any interim mitigation. Restrict exposure of the affected system where you can. Watch your logs for signs of exploitation. Apply the patch as soon as it is tested and available.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.