A zero-day vulnerability is a software flaw that attackers find and exploit before the vendor knows it exists or has a patch ready. There is no fix waiting in the wings and no warning, so the first sign of trouble is often the attack itself. For a UK business, that single fact changes how you have to think about defence. You cannot patch your way out of a risk nobody has told you about yet.

Table of Contents
What Makes a Vulnerability a “Zero-Day”?
The name comes from the vendor’s position when the flaw surfaces. They have had zero days to build and ship a fix. The weakness was either discovered independently by attackers or leaked before the maker could respond. Google’s Threat Intelligence Group (GTIG) defines a zero-day as a vulnerability that was maliciously exploited in the wild before a patch was made publicly available.
Once a patch exists, the clock resets. The same flaw exploited after a fix is released is usually called an “n-day” vulnerability instead. A zero-day vulnerability only earns that name while the fix is still missing, so the danger comes from organisations being slow to install the update once one appears.
Zero-Day Vulnerability vs Exploit vs Attack
These three terms get used interchangeably, but they describe different stages of the same problem.
- Zero-day vulnerability: the underlying flaw in the code, hardware or firmware itself.
- Its exploit: the working code or technique an attacker writes to actually take advantage of that flaw.
- The resulting attack: the real-world use of that exploit against a target, such as planting malware or stealing data.
A vulnerability can exist for months before anyone builds an exploit for it. Once an exploit exists, it can sit unused until a threat actor decides to launch an attack. Each stage narrows the group of people who know about the problem, and each one raises the stakes for defenders who are still in the dark.
How Are Zero-Day Vulnerabilities Discovered?
Three groups tend to find them first, and their intentions differ enormously.
- Security researchers and bug bounty hunters, who typically report the flaw privately to the vendor and give them time to fix it before publishing details.
- Commercial surveillance and exploit vendors, who sell knowledge of the flaw to governments or other paying customers rather than disclosing it.
- Criminal or state-backed threat actors, who find the flaw themselves through code review, fuzzing or reverse engineering, and use it directly for financial gain or espionage.
Which group gets there first shapes what happens next. A researcher who follows responsible disclosure buys the vendor time. A threat actor who finds the same zero-day vulnerability first buys themselves a head start against every organisation running that software.
Why Zero-Days Are a Growing Problem
The numbers back up the sense that this threat is not slowing down. GTIG tracked 90 zero-day vulnerabilities exploited in the wild during 2025, up from 78 in 2024, though still below the record of 100 set in 2023. What has changed is the target: 43 of 2025’s zero-days, or 48%, hit enterprise software and appliances, up from 46% the year before. Consumer devices and apps still make up the rest, but the enterprise share keeps climbing.
GTIG’s own analysis found that big technology vendors experienced the most zero-day exploitation in 2025, with security and networking vendors close behind. Cisco and Fortinet remain commonly targeted networking and security vendors, while Ivanti and VMware continue to see exploitation of their products. That pattern matters for any business that runs an edge firewall, VPN gateway or remote access appliance from one of these vendors. Those products sit exactly where an attacker wants to land first, as UK organisations running SonicWall’s SMA 1000 appliances found out when two zero-days there came under active attack.
Speed has also shifted against defenders. CrowdStrike’s 2026 Global Threat Report documented a 42% year-over-year increase in zero-days exploited before public disclosure. Adversaries are weaponising vulnerabilities for initial access, remote code execution and privilege escalation ahead of any public warning. The window where a defender could reasonably expect advance notice keeps shrinking.
What Should Your Business Do About Zero-Day Risk?
You cannot patch a zero-day vulnerability nobody has told you about. The useful work happens elsewhere.
- Assume something will get through. Layer detection and response behind your perimeter rather than treating firewalls and endpoint protection as a single line of defence.
- Cut your exposed attack surface. Every internet-facing service, VPN appliance and admin panel is one more thing a zero-day could land on. Decommission what you do not need.
- Patch fast once a fix exists. The National Cyber Security Centre recommends a risk-based approach that prioritises internet-facing services first, alongside regular vulnerability assessments across your estate, generally at least monthly.
- Track what is actively being exploited. The CISA Known Exploited Vulnerabilities catalogue is maintained as the authoritative source of vulnerabilities exploited in the wild. It is designed to feed straight into an organisation’s patch prioritisation.
- Test your defences under realistic conditions. A penetration test will not predict which zero-day appears next. It does show whether your monitoring, segmentation and incident response would actually catch an attacker who got past the perimeter through one.
That last point is where a scoped security review earns its keep. If your last test only checked whether the front door was locked, it will not tell you much. It will not show whether someone who slips through an unpatched edge device could move freely once inside. Aardwolf Security runs penetration tests built around exactly that assumed-breach question. A short conversation with our team is enough to work out where your zero-day exposure actually sits.
Frequently Asked Questions
Is a zero-day vulnerability the same as a zero-day exploit?
No. The vulnerability is the underlying flaw. The exploit is the code or technique built to take advantage of it. A flaw can exist for a long time before anyone writes a working exploit for it.
Can antivirus software stop a zero-day attack?
Sometimes, if the attack behaves in a way the software’s behavioural detection recognises. But signature-based tools that look for known malware will usually miss a genuinely new exploit, which is why layered defences and monitoring matter more than any single tool.
How long do zero-days usually stay unpatched?
It varies enormously, from hours to years. That depends on how quickly the flaw is reported, how complex the fix is, and how the vendor prioritises it. Once a patch ships, the pressure shifts to how fast affected organisations install it.
Are small businesses actually at risk from zero-days?
Yes. Many zero-days target widely used software and edge devices rather than specific organisations, so any business running the affected product is exposed, regardless of size. Smaller organisations are often slower to patch, which extends the window of risk.
Does a penetration test find a zero-day vulnerability?
Not directly. A test cannot uncover a flaw nobody in the industry knows about yet. What it can do is show whether your wider defences, detection and response would limit the damage if a zero-day vulnerability were used against you.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.