Zero-Day Exploitation
Zero-day exploitation uses a vulnerability for which the vendor has no patch yet, or does not know exists. The name says how much time the defense had to prepare: zero days. In practice a victim can be doing everything right, keeping systems and applications up to date, and still be exposed.
Term
description · examples · notesZero-day exploitation uses a vulnerability for which the vendor has no patch yet, or does not know exists. The name says how much time the defense had to prepare: zero days. In practice a victim can be doing everything right, keeping systems and applications up to date, and still be exposed.
Description
That is why zero-day vulnerabilities are expensive, rare and valuable. They are usually kept for targets that justify the price: government institutions, large companies, supply chains, journalists, activists, financial systems or infrastructure. When they do appear in mass use, the window for reacting is short.
A defense against zero-day cannot rest on patches alone, because at the moment of the attack the patch does not exist. What matters is reducing the attack surface, segmentation, behavioral detection, limited rights and a response plan. When you do not know the exact flaw, you have to limit what its exploitation can lead to.
Examples
- An unknown vulnerability in a browser is used to install spyware with no visible interaction from the user.
- A vulnerability in a network device is exploited before the vendor publishes a patch.
- A popular library carries an unknown flaw that allows servers to be compromised before the community even works out what the problem is.
Notes
- Zero-day does not automatically mean magic. After exploiting the vulnerability the attacker still has to move, stay present and extract something. That is where the defense can catch them.
- If a system was exposed to the vulnerability before the patch was published, the question is not only when the patch goes on, but whether a compromise has already happened.
Mentioned in the news
- 6. JUN 2026. Planeta Odmetnik pristupa SYSTEM nalogu kroz Windows Defender →
- 22. MAJ 2026. Zero-day u Microsoft Defenderu: Napadač navodi ugrađeni antivirus da mu otključa SYSTEM →
- 22. MAJ 2026. Jedan kivni istraživač, šest Microsoftovih zero-day ranjivosti za šest nedelja — i poručuje da nije završio →
- 18. MAJ 2026. Istraživač objavio YellowKey exploit za zaobilaženje BitLockera →
- 18. MAJ 2026. Project Zero prikazao zero-click exploit lanac za Pixel 10 →
- 30. APR 2026. Microsoft potvrdio aktivnu zloupotrebu Windows Shell ranjivosti →
- 19. APR 2026. Tri Microsoft Defender zero-day ranjivosti aktivno zloupotrebljene →
- 16. APR 2026. Adobe hitno zakrpio zero-day propust u Acrobatu i Readeru →
- 2. APR 2026. Google zakrpio Chrome zero-day koji se već aktivno zloupotrebljava →
- 2. APR 2026. Napadači zloupotrebili TrueConf zero-day za slanje lažnih nadogradnji →
- 29. MAR 2026. Apple upozorava korisnike starijih iPhone uređaja na aktivne web napade →
- 28. MAR 2026. Kritične Ivanti EPMM zero-day ranjivosti omogućavaju udaljeno izvršavanje koda →
- 23. MAR 2026. Interlock je zloupotrebljavao Cisco FMC zero-day više od mesec dana pre zakrpe →
- 20. MAR 2026. Cisco FMC ranjivost CVE-2026-20131 korišćena kao zero-day u Interlock ransomware napadima →
- 13. MAR 2026. Google zakrpio dve Chrome zero-day ranjivosti koje su već korišćene u napadima →
- 5. MAR 2026. Google: tokom 2025. u napadima iskorišćeno 90 zero-day ranjivosti →
- 27. FEB 2026. Cisco zakrpio Catalyst SD-WAN zero-day iskorišćen u ciljanim napadima →
- 18. FEB 2026. Dell zero-day iskorišćen u Brickstorm kampanji →
- 17. FEB 2026. Google zakrpio prvi Chrome zero-day ove godine →
- 13. FEB 2026. Apple objavio zakrpu za aktivno eksploatisani zero-day propust →
- 15. JUL 2026. Microsoft u julu zakrpio rekordnih 570 propusta — dve 0-day ranjivosti već u aktivnim napadima →
- 8. JUL 2026. Napadi na Cisco SD-WAN: perimetar mreže kao najvrednija meta →
- 22. MAJ 2026. Google zakrpio dve kritične Chrome ranjivosti kroz koje maliciozna veb-stranica može da provali u vaš sistem →
- 15. APR 2026. Storm-1175 koristi zero-day i N-day propuste za brzu isporuku Medusa ransomware-a →
- 15. APR 2026. Microsoft zakrpio SharePoint zero-day i još 168 ranjivosti u aprilskom Patch Tuesday ciklusu →
- 15. APR 2026. Microsoft objavio Windows 10 KB5082200 ESU zakrpu sa ispravkama za april i dve zero-day ranjivosti →
- 4. FEB 2026. CISA: ransomver grupe aktivno koriste VMware ESXi sandbox escape ranjivost →
Techniques
carried out with 6Techniques used to carry it out. Select one to open its page.