What is a zero-day exploit?
This article explains what a zero-day exploit is, how attackers use zero-day vulnerabilities to gain access, and how security teams can reduce the risk while waiting for a patch.
A zero-day exploit is a cyberattack that takes advantage of a software vulnerability before the vendor has released a patch, leaving security teams without an official patch to address the underlying flaw.
The key is that the vendor does not yet know the flaw exists, or knows but has not yet released a fix. An attacker can discover a vulnerability, actively work on an exploit, and deploy it while the vendor is still unaware. The gap between when an attacker has a working exploit and when a patch is available to fix the issue, is what makes zero day exploits dangerous. During this window, there is no official advisory, or a patch for vulnerability management tools to detect.
Zero Day Vulnerability, Exploit, and Attack: What Each Term Means
These three terms appear together constantly in security reporting, but they describe different things.
Zero-day vulnerability: A zero-day vulnerability is a security flaw in software or hardware that can be exploited before a patch is available from the vendor. The vulnerability is the underlying weakness that gives an attacker an opportunity to compromise the affected system.
Zero day exploit: A zero-day exploit is the code, technique, or method used to take advantage of a zero-day vulnerability. An attacker can use the exploit before the vendor has released a fix, allowing the vulnerability to be exploited while defenders do not yet have an official patch to address it.
Zero day attack: A zero-day attack occurs when an attacker uses a zero-day exploit against an actual target. Depending on the vulnerability and the attacker's objective, exploitation can lead to code execution, unauthorized access, credential theft, data theft, or further movement through the environment.
The distinction matters because your response options differ at each stage. The vulnerability is the risk, the exploit is the mechanism, and the attack is the outcome. A vulnerability can exist without a known exploit, and an exploit can exist without an active attack. Understanding where an organization stands in that sequence shapes how their security team responds.
How do Zero-day exploits work
Before a zero day exploit reaches its target, it moves through a predictable sequence. Each stage represents a point where detection or containment may be possible.
- Discovery: A researcher, attacker, or third-party vendor finds a flaw in software, typically in an operating system, browser, or widely deployed application.
- Analysis: The researcher studies the flaw to understand how reliably it can be used, what level of access it grants, and whether existing defences are likely to detect it.
- Weaponization: The exploit is then packaged as a script, a malicious document, or a network request designed to trigger the bug predictably.
- Delivery: The exploit reaches its target through phishing emails, compromised websites, malicious software updates, or through direct network access.
- Exploitation: The attacker gains access and common actions include code execution, privilege escalation, credential theft, or lateral movement.
What happens after the initial exploit matters as much as the exploit itself. Attackers who gain entry through a zero day vulnerability still need to move through the environment to reach their real targets. That movement depends on the environment they exploit: known vulnerabilities that have not been patched, misconfigurations that open lateral paths, and software that no longer receives security updates. Reducing these conditions is what limits how far a zero day attack can go.
Zero-Day Exploit Exposure: Why the Window Before a Patch Matters
A zero-day creates a gap that normal vulnerability management cannot immediately address. When a vulnerability is being actively exploited, and no patch exists, security teams have to reduce the attack surface and limit what an attacker can do until a fix becomes available.
Google Threat Intelligence tracked 90 zero-day vulnerabilities exploited in the wild in 2025, up from 78 in 2024. The concern is not just the number of zero-days, but, the fact that each actively exploited zero-day can leave affected systems exposed while defenders are still waiting for a vendor fix.
Signature-based antivirus may not recognize a zero day exploit at the point of entry, because there is no signature to match if the vulnerability has not been publicly disclosed. Intrusion detection systems tuned to recognise patterns face the same limitation, and threat intelligence feeds cannot warn organizations about something that has not surfaced yet. Modern endpoint security tools can detect suspicious behaviour and exploit techniques in memory, but during the initial exposure window, the absence of a patch often means the absence of reliable detection.
Until a patch exists, the goal is therefore to contain the exposure rather than eliminate the vulnerability. That means reducing reachable attack surface, applying available mitigations, strengthening configurations, and limiting the paths an attacker can use to move through the environment.
What Security Teams Can Do Before a Patch Exists
The absence of a patch does not mean the absence of options. Most successful zero day attacks rely on more than just the actual vulnerability. They exploit the conditions around it. A system with all known vulnerabilities patched, correctly configured, and actively monitored is significantly harder to compromise, even when a zero day is in play.
These five steps give an idea of what security teams can do to stay vigilant and minimize the severity of a zero-day attack.
1. Keep known vulnerabilities patched
Zero day exploits rarely work in isolation. Attackers use the initial access to pivot through known vulnerabilities towards their real targets. A consistent patch management program closes those secondary paths. When known vulnerabilities are remediated quickly across endpoints, servers, and network devices, the blast radius of a zero day shrinks, even when the entry point itself cannot be patched yet.
2. Deploy vendor recommended mitigations quickly
When a zero day becomes publicly known, the vendor typically issues a mitigation advisory before the patch is ready. These advisories involve configuration changes, like disabling a specific protocol, closing a port, modifying a registry setting, and restricting access to an affected service. Having a reliable system to test and deploy these workarounds quickly is one of the most practical defences available during the gap between vulnerability disclosure and patch.
3. Isolate and segment vulnerable systems
When a zero-day is active and no patch is available yet, network segmentation reduces the movement of the attacker. Restricting network access for vulnerable systems to just the minimum required for operations, limits the blast radius before a fix exists. This is applicable specifically to edge devices like VPNs and firewalls, which have been the most targeted category in recent years, accounting for 44% of zero-days in 2024, as per Google's Threat Intelligence Group's 2025 study.
4. Hunt for pre-patch exploitation
Many zero-days are exploited before public disclosure. Attackers with access to the exploit have been operating in environments for weeks or months before the CVE is announced. When a zero-day becomes public, security teams should search historical logs using the attack signatures and behavioural patterns published in the vendor advisory.
5. Act on threat intelligence early
The CISA Known Exploited Vulnerabilities catalog (cisa.gov/known-exploited-vulnerabilities-catalog) is updated continuously and reflects what attackers are actively using in the wild. Organizations that act quickly when a vulnerability is added to the KEV catalog consistently reduce their exposure window compared to teams that rely solely on scheduled patch cycles.
What Happens After a Zero-Day Vulnerability Is Patched?
Organizations that patch slowly remain exposed long after a fix is available. When a patch ships, attackers shift from exploiting the zero day to targeting organizations that have not yet applied it. According to the 2026 Verizon DBIR, organizations took a median of 43 days to fully remediate critical known exploited vulnerabilities in 2025, up from 32 days in 2024. The share of critical vulnerabilities fully resolved fell from 38% to 26% over the same period. The patch existing and the patch being deployed are two different things.
When a zero day patch is released, security teams should:
- Identify every affected asset across the environment
- Test the patch in a staged environment where possible
- Roll back interim mitigations that are no longer needed
- Deploy the patch starting with the highest risk and most exposed assets.
- Verify remediation across all the affected systems
Speed matters more here than for routine patching. Once a patch is public, attackers can reverse engineer it to build exploits targeting organizations that have not applied it. While these initial attacks occur before a fix exists, the publication of a patch instantly shifts the threat, triggering a wave of N-day exploits that aggressively target organizations that were slow to deploy the update.
How Do Vulnerability Management Tools Help With Zero-Day Exploits?
Vulnerability management tools can help security teams identify affected assets, assess exposure, apply available patches, and track remediation status when a zero-day vulnerability is disclosed. While these tools cannot eliminate a vulnerability before a vendor releases a fix, they can help security teams understand where the vulnerability exists and coordinate the response across the environment.
When a zero-day is disclosed, vulnerability management tools can help with:
- Identifying affected assets: Determine which endpoints, servers, applications, and other systems are running affected software.
- Assessing exposure: Provide visibility into the scope of the vulnerability across the environment, helping security teams identify systems that require immediate attention.
- Applying temporary mitigations: Where a vendor provides a workaround, security teams can use vulnerability management tools to deploy or track those mitigations until a permanent fix is available.
- Tracking remediation: Maintain visibility into which systems have been mitigated, patched, or remain exposed as the response progresses.
- Deploying the patch when available: Once the vendor releases a fix, the tool can help identify affected systems and coordinate patch deployment across the environment.
The important point is that vulnerability management tools do not make a zero-day vulnerability disappear. Their role is to reduce the time between disclosure, exposure assessment, mitigation, and permanent remediation.
How Vulnerability Manager Plus Helps With Zero-Day Exploits
ManageEngine Vulnerability Manager Plus (VMP) helps security teams respond to zero-day vulnerabilities by identifying affected assets, providing prebuilt mitigation scripts before a patch is available, notifying teams when a patch is released, and helping deploy the patch across affected systems. This helps reduce the time between zero-day disclosure and remediation.
1. Zero day mitigation dashboard
When a zero day is disclosed, ManageEngine's security researchers verify the details and add them to the central vulnerability database. The data synchronizes with the VMP server, so security teams see affected assets in one place without having to piece together exposure from multiple sources.
2. Prebuilt mitigation scripts
Before a patch is available, VMP provides prebuilt mitigation scripts that can be deployed to all affected machines. These scripts harden systems, alter registry values, close vulnerable ports, and disable legacy protocols, removing the need for teams to write, test, and distribute workarounds manually during the exposure window.
3. Zero day patch notification
When a vendor releases a patch for a vulnerability previously labelled as a zero day, VMP alerts the team in the console's notification bar. Teams can then revert the interim workaround and deploy the patch to fix the vulnerability permanently.
4. Automated patch deployment
When a patch is released for a previously unpatched zero day, VMP handles the rollout across all affected endpoints and servers. Teams do not need to manually track which systems were covered and which were missed.
