GyaanamKnowledge for All
Back to Internal SecurityAll concepts

Zero-Day Vulnerability

Syllabusbasics of cyber security

Internal SecurityPublished 4 August 2026

A zero-day vulnerability is a previously unknown flaw in software, hardware, or firmware for which an effective vendor patch is not yet available. A zero-day exploit is the code or technique used to take advantage of that flaw; using it against a target constitutes a zero-day attack. The name indicates that defenders have had zero days of advance time to correct the weakness when exploitation begins or becomes known.

How a zero-day attack develops

The risk exists during the interval between discovery of the flaw and deployment of an effective fix, often called the window of exposure.

  • An attacker may discover the flaw, develop an exploit, and use it before the vendor or defenders know about it.
  • After detection or responsible disclosure, the vendor investigates the flaw and releases a patch or mitigation.
  • Once a fix exists, unpatched systems can remain vulnerable, although the flaw is no longer strictly an unknown zero-day weakness.

Why it is dangerous

  • Traditional signature-based detection may initially miss the attack because its code or behaviour has not previously been catalogued.
  • The absence of an immediate patch limits the defender's ability to remove the underlying weakness.
  • A successful exploit may enable unauthorised access, data theft, service disruption, privilege escalation, or installation of malware.

Defence and risk reduction

No single control can eliminate zero-day risk, so organisations require defence in depth.

  • Behaviour-based monitoring and endpoint detection can identify suspicious activity without relying only on known signatures.
  • Least privilege, network segmentation, and application allowlisting can restrict an exploit's reach and consequences.
  • Asset inventories, secure configurations, tested backups, and incident-response plans improve organisational resilience.
  • Rapid testing and deployment of security patches reduce exposure once a remedy becomes available.

How UPSC asks this

Prelims

Distinguish a zero-day vulnerability from a zero-day exploit, zero-day attack, and an ordinary unpatched vulnerability.

Mains

Explain why such vulnerabilities challenge cyber security and assess defence-in-depth measures for reducing their impact.

Keep reading

The news behind topics like this, explained every morning

Every morning Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 15 days are free.

Sign up