home/glossary/Zero-day attack

Zero-day attack

nounid 4704·updated May 9, 2026
candidate

An attack on a piece of software that has a vulnerability for which there is no known patch.

MWE

Classifications

Entity Type

Vulnerability95%rule-basedr:entity.vulnerability.cve.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
Zero-day attacks
possessive
Zero-day attack's
pluralpossessive
Zero-day attacks'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
A zero-day (or zero-hour or day zero) attack or threat is a computer threat that tries to exploit computer application vulnerabilities that are unknown to others or undisclosed to the software developer. Zero-day exploits (actual code that can use a security hole to carry out an attack) are used or shared by attackers before the software developer knows about the vulnerability.
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
An attack on a piece of software that has a vulnerability for which there is no known patch.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.