Zero-Day Vulnerability
A vulnerability unknown to the vendor, with no available patch, at the time it is discovered or exploited.
A zero-day vulnerability is one the affected vendor has had zero days to fix — either because it was just discovered or because it is being actively exploited before public disclosure. Zero-days are especially dangerous because standard vulnerability scanning, which relies on known signatures and published CVEs, cannot detect them by definition; they typically surface through manual testing, threat intelligence, or after exploitation is observed in the wild. A mature VAPT program plans for zero-days by combining continuous scanning for known issues with periodic manual testing capable of finding novel ones, and by having a fast triage and patching process ready for when a zero-day affecting your stack is disclosed.
Ready to see Venstap in action?
Get a guided walkthrough of scanning, triage, and reporting on your own assets.