The Canadian Encyclopedia — neutral, cited, updated
July 26, 2026Sources cited
Canadianwire.
Canada’s encyclopedia & explainer
HomeTechnology & InternetCybersecurityZero day
Technology & Internet • Cybersecurity

Zero day

A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched.

By Ethan Anderson| Reviewed by Olivia Bennett, Standards & Fact-Checking Lead| Updated July 26, 2026|2 min read| Fact-checked

A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched. The term is also used for the exploit or attack that takes advantage of such a flaw before defenders have a fix. Zero-day issues are especially dangerous because standard signature-based defences may not detect them initially.

Meaning and usage

In cybersecurity, zero day refers to a vulnerability that is not yet known to the vendor or has no available fix. The phrase is also used more broadly for the exploit or attack built around that vulnerability.

How zero-day attacks work

Attackers identify or purchase knowledge of an undisclosed flaw and use it before a patch exists. Because defenders have had no time to respond, the vulnerability can be exploited quietly until it is discovered and mitigated.

Why zero-day vulnerabilities matter

Zero-day flaws are considered high risk because they can be used for malware installation, unauthorized access, data theft, and other intrusions. They are difficult to block with traditional reactive defences before detection signatures or patches exist.

Defence and mitigation

Security teams typically rely on behaviour-based detection, network monitoring, application hardening, rapid patching once fixes are released, and layered controls rather than signatures alone. These measures reduce exposure but cannot eliminate the risk before discovery.

Key facts

  • A zero-day vulnerability is a flaw unknown to the vendor or defenders at the time it is found or exploited.
  • A zero-day exploit is the method or code used to take advantage of that flaw.
  • A zero-day attack occurs when an attacker uses the exploit before a patch is available.
  • Zero-day issues are especially dangerous because standard signature-based defences may not detect them initially.
  • The term applies to vulnerabilities in software, hardware, and firmware.
🍁
Canadian context

Zero-day vulnerabilities affect Canadian individuals, businesses, government systems, and critical infrastructure, and Canadian cybersecurity guidance commonly treats them as high-priority threats requiring layered defences and rapid patching when fixes become available.

Frequently asked questions

What is a zero-day vulnerability?
It is a security flaw that is unknown to the vendor or defenders and has no available patch at the time it is discovered or exploited.
What is a zero-day exploit?
It is the technique or code used to take advantage of a zero-day vulnerability.
What is a zero-day attack?
It is an attack that uses a zero-day exploit before the affected system has been patched.
Why is it called a zero day?
Because defenders have had zero days to prepare or release a fix before the flaw is used against them.
Can zero-day flaws affect hardware as well as software?
Yes. Sources describe zero-day vulnerabilities in software, hardware, and firmware.

References

  1. Wikipediahttps://en.wikipedia.org/wiki/Zero-day_vulnerability
    Supports: Basic definition of zero-day vulnerability, exploit, and attack
  2. RANDhttps://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdf
    Supports: Meaning of zero-day vulnerabilities and the term’s reference to days known to the vendor
  3. CrowdStrikehttps://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/zero-day-exploit/
    Supports: Distinction between vulnerability, exploit, and attack
  4. Splunkhttps://www.splunk.com/en_us/blog/learn/zero-day.html
    Supports: Unknown vulnerabilities, lack of patches/signatures, and defence considerations
  5. SentinelOnehttps://www.sentinelone.com/cybersecurity-101/threat-intelligence/zero-day-vulnerabilities-attacks/
    Supports: Attacks before patches and common impacts
  6. HPEhttps://www.hpe.com/us/en/what-is/zero-day-vulnerability.html
    Supports: Definition of zero-day vulnerability and lack of patch
  7. Tenablehttps://www.tenable.com/cybersecurity-guide/principles/zero-day-vulnerability
    Supports: Known vulnerability without a patch and the 'zero days' concept
  8. Orca Securityhttps://www.orca.security/glossary/zero-day-vulnerability/
    Supports: Zero-day applicability to software, hardware, and firmware