Just out todayClimate & energy tech: We ran the Ibadan solar forecast ourselves. Every number came back.AI agents & MCP: What a 49.1% attack rate does not tell youCybersecurity: The MCP scanner number that should worry you

Explainer/Cybersecurity

What is a zero-day vulnerability?

A zero-day is a software hole the maker does not know about, so no fix exists yet. Learn how one is found and used, why most attacks never need one, and how to limit the damage.

The short answer

A zero-day vulnerability means a flaw in software that the maker does not yet know about, so there has been zero days to build a fix. Anyone who finds it first can use it while every user stays open. Once the maker is told and ships an update, the flaw stops being a zero-day and becomes a known problem to patch.

Grade 5 reading level5 min read

A builder puts up a block of flats, and he fits good doors and strong locks. But one back window has a faulty latch, and he does not know. A thief walking past notices it first.

Everyone in the building is at risk. Nobody can fix the window, because nobody has been told it is broken. The builder has had zero days to work on it.

That is a zero-day, and it is a hole in software that the maker does not know about yet. The name counts the days the maker has had to build a repair. Therefore, the count is zero.

What a zero-day actually means

Software is written by people, so it contains mistakes, and some mistakes are harmless. However, a few let an outsider do something they should not do, such as read your files or take over the machine.

A mistake like that is called a vulnerability. It becomes a zero-day when someone finds it before the maker does, and the maker has no fix ready.

The clock starts when the maker learns of the hole. Until then, every user is open, and there is no update to install, because none exists.

Three words people mix up

These three words get used as if they mean the same thing, but they do not.

  • A vulnerability is the flaw itself. It is the faulty latch.
  • An exploit is the method that abuses the flaw. It is the trick of lifting the window just so.
  • An attack is somebody using that exploit against a real target. It is the burglary.

A flaw can sit in code for years and never be found. Many are found by honest people and quietly repaired, and only a small share ever become an attack.

How a zero-day plays out, step by step

The story usually runs in this order.

  1. Someone finds the flaw. It may be a researcher, a criminal or a government team.
  2. They build an exploit and test it.
  3. They use it quietly. Loud use gets noticed and burns the flaw.
  4. A defender spots strange behaviour and works backwards to the cause.
  5. The maker is told and starts building a fix. Now the clock runs.
  6. The fix ships. The details often go public at the same time.
  7. Attackers read the fix, work out the hole, and hunt for machines that have not updated.

Step seven surprises people. Why does a fix make things worse for a while? Because the fix describes the problem. Therefore, any machine left unpatched is now an easy target, and it stays easy for years.

Who finds them, and who pays for them

Three groups hunt for these flaws, and they want different things.

Security researchers look for them to get them repaired. Most large software firms run a bug bounty, which is a reward paid for a reported flaw. The researcher gives the maker time to fix it before saying anything in public. A common practice is to wait around three months.

However, criminals look for flaws that lead to money. That means banking apps, email systems and anything that helps spread ransomware across a company.

Governments buy them too, through brokers who pay well. The highest prices go to attacks on phones that work with no click from the owner. This is why a phone flaw is treated so seriously.

Why most break-ins do not use a zero-day

Here is the part the news rarely says. Zero-days are rare and costly, and most successful attacks do not need one.

Why not? Because plenty of easier doors are open. A password reused across sites. A staff member fooled by phishing. A server missing an update that shipped two years ago. Attackers pick the cheapest route, and the cheapest route is almost never a fresh flaw.

Once a flaw is public it gets a tracking number, known as a CVE. Attackers then scan the internet for machines that still carry it. THE OLD KNOWN HOLE HURTS MORE PEOPLE THAN THE NEW SECRET ONE.

What you can do about a hole nobody knows about

You cannot patch a flaw that has no patch, so change the question. Ask how much harm one break-in could do, and then shrink that number.

  1. Turn on automatic updates, then restart the device so they take effect.
  2. Remove software you do not use. Less code means fewer holes.
  3. Work from an account without admin rights for daily tasks.
  4. Keep one backup offline, so a bad day does not become a lost year.
  5. Split your network so one broken machine cannot reach everything.

Points three and five come straight from zero trust security. Assume something will get through, and then make sure it lands in a small room.

How to read the news about zero-days

Reporters call almost any new attack a zero-day, and often it is not one. Ask two questions when you see the word.

First, is a fix available? If yes, the story is about updating, and you can act today. Second, is the flaw being used in real attacks? A flaw found by a researcher and quietly repaired is a good news day, even though it sounds alarming.

One real case shows the pattern. In late 2021 a hole was found in Log4j, a logging tool built into a huge amount of business software. Teams across the world spent that December hunting for copies of it inside their own systems. Many did not know they were using it at all.

That is the honest lesson, and you cannot fix what you do not know you run. Our guide to what cybersecurity is covers the wider set of habits.

What to check today

Open the settings on your phone and your laptop, and find the update page. Turn on automatic updates and then restart both devices, because many fixes only take hold after a restart.

Then write a short list of the software your work depends on, and add where each one gets its updates from. When the next big flaw is announced, that list turns a panicked week into a calm afternoon.

Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.

What to remember
  • A zero-day is dangerous because no patch exists, so defence has to rely on limiting damage rather than closing the hole.
  • Most successful break-ins use old flaws that already have a fix, so regular updating protects far more people than zero-day worry does.
  • A published fix makes the flaw public, which is why any machine left unpatched after an update becomes an easier target than before.

Questions people ask

Why is it called a zero-day?

The name counts the days the software maker has had to work on a repair. When a flaw is being used before the maker knows about it, that count is zero. Once the maker is told, the clock starts running and the flaw is on its way to becoming an ordinary patched bug.

What is the difference between a zero-day and an exploit?

The zero-day is the flaw itself, sitting in the code. The exploit is the method or the program written to take advantage of that flaw. A flaw with no working exploit is a risk on paper. A flaw with a reliable exploit is a live danger.

Can antivirus software stop a zero-day?

Traditional antivirus looks for known bad files, so it often misses a brand new attack. Modern tools also watch behaviour, such as a document trying to start a hidden program, and that can catch an unknown flaw in use. Neither approach is certain, which is why limiting access and keeping offline backups matters.

How much are zero-days worth?

Prices vary widely and are rarely published, but the pattern is clear. Flaws that take over a modern phone with no action from the owner sell for far more than flaws in less common software. Legitimate bug bounty programmes usually pay less than private brokers do.

About the author

Mark Alex

Mark Alex is the founder and Managing Director of Real Biz Digital, a technology company operating out of Nairobi since 2018. He works in agentic AI and the Model Context Protocol, AI governance, enterprise software architecture and cybersecurity. He holds an MSc in Mechatronical Engineering from Obuda University in Budapest and a BSc in IT, Forensic Technology and Cybercrime, from USIU-Africa in Nairobi, and has published IEEE conference research on an AI-powered digital twin for greenhouse systems. He is the author of seven books. Between 2020 and 2024 he mentored more than 200 university students and interns in Nairobi. He writes every Just Out Tech article from the original research paper.