Glossary

Zero-day

A vulnerability unknown to the vendor, for which no patch exists at the time it is exploited. Zero-day attacks are especially dangerous because no signature-based defense detects them. When such a flaw is actively exploited, it is often added to CISA's KEV catalog to force emergency patching across organizations.

Why a zero-day is more dangerous than a regular CVE

A published CVE usually comes with a patch: the race is to update before an exploit circulates. A zero-day flips that balance — the attacker exploits the flaw while the vendor is still unaware and no fix exists. Signature-based perimeter defenses are blind to it, and only defense in depth — segmentation, least privilege, behavioral detection — limits the impact until a patch ships.

What it means for an HR SaaS vendor

Your dependencies (framework, application server, libraries) may contain a zero-day being exploited elsewhere before it is even documented. Tracking CISA's KEV catalog and the advisories of your critical components lets you react within hours of a disclosure rather than weeks. A real-world audit also verifies that exploiting a single flaw does not grant access to all of your tenants' data.

Frequently asked questions

What's the difference between a zero-day and a CVE?

A CVE is an identifier assigned to a known vulnerability, typically patched or being patched. A zero-day is a flaw exploited before the vendor is aware of it and before a fix is available. A zero-day usually receives a CVE once it is publicly disclosed.

How do you defend against a flaw with no patch yet?

By reducing the attack surface (minimal exposed services), applying least privilege and segmentation to contain exploitation, and monitoring for anomalous behavior rather than only known signatures. These measures limit a zero-day's impact while you wait for the official patch.

Related Pages

Other Terms

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit