Zero-Day
CriticalZero-Day
Definition
A Zero-Day (0-day) vulnerability is a security flaw that is unknown to the software vendor and for which no patch is available. The term 'zero day' means the developer has had zero days to fix the problem. These vulnerabilities are extremely valuable both to attackers and in legitimate security markets.
Impact
Examples
Historic Zero-Day examples
Log4Shell (CVE-2021-44228) was a zero-day in Apache Log4j that enabled RCE and affected millions of Java applications globally. Before its disclosure, it is estimated to have been actively exploited for at least two weeks. The highest-paying bug bounty programs usually pay the largest amounts for critical zero-days.