What is a zero-day vulnerability?
A zero-day vulnerability is a security flaw in software, hardware or firmware that attackers can exploit before the maker has released a fix. So users have no patch to install when the attacks begin.
Also known as: zero-day, 0-day, zero-day exploit
Researched and fact-checked by AI, with no human review. 8 sources listed below. How we verify
Last updated
What the term means
The US National Institute of Standards and Technology (NIST) glossary describes a zero-day attack as one that exploits a previously unknown hardware, firmware or software vulnerability. Google Threat Intelligence Group (GTIG) publishes a yearly count. Its review of 2025 was published in March 2026. It defines a zero-day as a vulnerability that was maliciously exploited in the wild, meaning in real attacks, before a patch was publicly available. Mandiant, part of Google Cloud, used a separate label, n-day, in an October 2024 analysis for vulnerabilities first exploited after a patch is available.
Why it matters
When no patch exists, routine updating cannot stop an attack. GTIG tracked 90 zero-days exploited in 2025, more than the 78 it counted for 2024 and fewer than the record 100 in 2023. Of the 2025 total, 43, or 48%, were in enterprise software and appliances. For the first time since it began tracking, GTIG attributed more zero-day exploitation to commercial surveillance vendors than to traditional state-sponsored espionage groups.
The US Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities catalog, a public list of flaws exploited in the wild. It listed 1,734 entries when checked on October 6, 2026. A CISA directive dated June 10, 2026, BOD 26-04, sets risk-based repair timelines for federal civilian agencies. Catalog status is one of four factors.
Where things stand in 2026
AI models are now used to search for flaws. On April 7, 2026, Anthropic announced Project Glasswing. It said Claude Mythos Preview had found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. At the time, it had no plans to make that model generally available. On October 6, 2026, Anthropic said its partners had found at least 129,000 verified vulnerabilities between April and July 2026. The figure is drawn from reports by a subset of partners. These are the company's own claims.
GTIG tracks exploitation separately. In an analysis published on September 30, 2026, it said zero-day exploitation averaged 11 per month from January to August 2026, compared with 8 per month in 2025. It called the increase marginal. It reported a jump to 22 in August. It said growth in exploitation was concentrated in faster weaponization of n-days. GTIG said it is possible that attackers are using AI tools to analyze patches and disclosure announcements for that purpose.
Sources
- zero-day attack - Glossary | CSRC, NIST Computer Security Resource Center
- Look What You Made Us Patch: 2025 Zero-Days in Review, Google Threat Intelligence Group (Google Cloud Blog)
- How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends, Mandiant (Google Cloud Blog)
- Known Exploited Vulnerabilities Catalog, Cybersecurity and Infrastructure Security Agency (CISA)
- BOD 26-04: Prioritizing Security Updates Based on Risk, Cybersecurity and Infrastructure Security Agency (CISA)
- Project Glasswing: Securing critical software for the AI era, Anthropic
- Expanding the Cyber Verification Program, Anthropic
- Vulnerability Discovery and Exploitation Trends in the AI Era, Google Threat Intelligence Group (Google Cloud Blog)