Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Proper Zero Day Vulnerability Definition current page
Link copied

The Proper Zero Day Vulnerability Definition

Apr 8, 2026

In cybersecurity, “zero day” is frequently diluted and used as a catch-all for any unpatched vulnerability. This article breaks down the three mandatory elements of a true zero day, illustrating why the distinction between a zero day and a known, but unpatched, flaw is critical for effective defense.

Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Zero Day Proper Definition
The Proper Zero Day Vulnerability Definition
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Getting This Cybersecurity Terminology Right is a Defensive Necessity

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Words matter in cybersecurity. The language we use shapes how boards allocate budget, how regulators write policy, how journalists frame incidents, and how organizations prioritize risk. Throughout the history of cybersecurity, arguably no term has been more abused, diluted, or misapplied than “zero day.”

It has become a headline accelerant, a marketing crutch, a faux message of urgency, and a convenient shortcut for discussing complex problems. Bluntly, when we get the definition wrong, we get the response wrong, and when we get the response wrong, we react with knee-jerk impulses that take focus away from what really matters.

Defining Zero Day Vulnerabilities: It’s Not a “New” Flaw

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

To be clear, a zero day vulnerability is not a synonym for “unpatched” or “critical vulnerability.” It is also not interchangeable with a “new” vulnerability or one that simply lacks a fix. A zero day is a very specific condition for multiple states of a vulnerability and associated exploitation and deserves precision when mentioned by a vendor or the media.

What is a Zero Day Vulnerability?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Straight Forwardly: A zero-day vulnerability is a previously unknown flaw in software or hardware that is potentially being actively exploited regardless of its severity, where the vendor (or responsible open-source community) has had “zero days” to develop and release a patch at the time of public disclosure. The emphasis on three elements: the threat is unknown to the vendor, it is potentially being exploited, and it is disclosed to the public. If you remove any one of these elements, it is no longer a zero day. For example, if the vulnerability has been patched—even if active exploitation is occurring—it is no longer a zero day but a known vulnerability following responsible public disclosure. Misusing the term—or creating hybrid phrases like “undisclosed” or “unknown” zero day—only muddies the waters for risk prioritization.

Why the Industry Confuses Zero Days with Known Vulnerabilities

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

This distinction matters because the industry routinely collapses three very different concepts into one overloaded term:

  1. Known, but unpatched, vulnerabilities: The industry sees CVEs reserved all the time for these situations. These flaws are publicly or privately disclosed, often cataloged, sometimes scored, and frequently prioritized for remediation by the vendor, based on severity and complexity to resolve. They are dangerous, but they are not zero days.
  2. Newly disclosed vulnerabilities: These may lack a patch, but are not yet known to be exploited in the wild. These are serious, but without a working exploit, they aren't categorized as zero days.
  3. True zero days: These are the vulnerabilities defenders didn’t know existed until threat actors demonstrated that knowledge through active exploitation (zero day exploit) before a patch was available.

The Cost of Sensationalism

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Why does this confusion persist and why do cybersecurity professionals and the media still get this wrong? Simply put, “zero day” sounds catastrophic. It implies an inevitability that fuels sensationalism. For the media, it suggests that no defense could have worked, creating a sense of extreme urgency to drive engagement. For organizations explaining a breach, it can sound like absolution—an excuse that nothing could have thwarted the attack and subsequent breaches. For vendors selling tools, it creates an artificial, absolute need for their specific solutions to be secured regardless of the moment of time.

For cybersecurity professionals, the cost of this misuse is not academic. When the term is used excessively, real zero days lose their urgency and budget. Security teams become desensitized and lose focus. Boards will begin to assume that breaches are unavoidable acts of nature rather than failures of control, hygiene, or prioritization. Regulators then struggle to distinguish genuine negligence from unforeseeable risk. Over time, the term loses its meaning.

The Reality of Modern Zero-Day Exploitation

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Today, true zero days are rare and expensive. They are usually not wasted on low-value targets. Instead, they are typically chained with other weaknesses, like identity-based attack vectors, delivered through trusted pathways and executed with stealth precision.

Nation states and top-tier cybercrime syndicates do not “burn” zero days casually. They use them only when the return justifies the cost of development and risk of public exposure. Once the vulnerability is disclosed and patched, their advantage as a weapon is lost. That reality alone tells us how careful we must be when invoking the term.

A proper understanding of zero days also changes the conversation around cyber defense. You cannot patch what you do not know exists; this is why disclosure is a part of the definition. However, you can reduce the impact of what you cannot patch or threats that have not been disclosed through cybersecurity best practices:

  • Least Privilege: Limits what exploit code or malware can interact with at the operating system and application level.
  • Segmentation: Prevents lateral movement after an initial exploitation.
  • Identity Controls: Limits the ability of an attacker to impersonate legitimate users.

These aren't just theoretical mitigations, they are the difference between a contained incident and a systemic failure when a zero day is truly exploited in an environment. Getting the definition right also forces honesty in post-incident analysis. These questions are uncomfortable, but necessary if organizations want to mature, rather than just repeat misunderstood terms:

  • Was the vulnerability truly unknown at the time of exploitation, or was it known but deprioritized?
  • Was exploitation confirmed, or merely assumed?
  • Was the absence of a patch the root cause, or was it the absence of compensating controls?

Clarity is a Defensive Capability

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

We must be disciplined. Reserve the term “zero day” for what it actually is—a vulnerability unknown to the vendor and organizations alike, actively exploited, with zero days to patch because remediation simply doesn't exist yet. Every other state has its own name and terminology: known vulnerability, unpatched vulnerability, misconfiguration, excessive privileges, or advanced persistent threat. These may sound less dramatic, but they are far more accurate when establishing the state of a threat.

In cybersecurity, clarity is a defensive capability. Threat actors thrive on confusion, obfuscation, whether technical, operational, or linguistic. If we cannot accurately define our threats, we cannot prioritize them intelligently and efficiently communicate the results to stakeholders. If we react loudly to the wrong things, we will inevitably ignore the risks that matter most. The definition of a zero day is not a semantic exercise. It is the line between sensationalism and effective prioritization.

You can’t patch a true zero day—but you can control what it can reach. BeyondTrust’s Identity Security Risk Assessment reveals the hidden privilege paths and identity exposures that determine how far an attacker—or an AI-powered exploit—can go. Sign up for our no-cost Identity Security Risk Assessment today to uncover your full identity attack surface and reduce the impact of the vulnerabilities you can’t predict.

About the Author

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Morey J. Haber is the Chief Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored five books: Attack Vectors: The History of Cybersecurity, Privileged Attack Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack Vectors. Morey has previously served as BeyondTrust’s Chief Security Officer, Chief Technology Officer, and Vice President of Product Management during his nearly 13-year tenure. In 2020, Morey was elected to the Identity Defined Security Alliance (IDSA) Executive Advisory Board to assist the corporate community with identity security best practices. He originally joined BeyondTrust in 2012 as a part of the eEye Digital Security acquisition where he served as a Product Owner and Solutions Engineer since 2004. Prior to eEye, he was Beta Development Manager for Computer Associates, Inc. He began his career as Reliability and Maintainability Engineer for a government contractor building flight and training simulators. Morey earned a Bachelor of Science degree in Electrical Engineering from the State University of New York at Stony Brook.

Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • Machine PAM: What It Is and Why It Matters
    Aug 29, 2025 Machine PAM: What It Is and Why It Matters
    Blog
    5m
  • Finding the Forgotten: Why Credential Discovery Is Essential To Securing Privileged Remote Access
    Dec 29, 2025 Finding the Forgotten: Why Credential Discovery Is Essential To Securing Privileged Remote Access
    Blog
    3m
Share this Article
  • Link
Tags
  • Glossary
  • Zero Day
  • Zero Day Attack
  • Zero Day Vulnerability
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.