Zero-day
A usable flaw the vendor has not disclosed or patched yet. Your window is not a blog post. It is exposure.
A zero-day is a software weakness that can be used before the vendor has published it or shipped a fix. Defenders have had zero days of notice. Attackers may have had months.
You cannot patch what does not exist yet. You can reduce blast radius: application control, least privilege, network segregation, compensating controls at a WAF or IPS where they actually fit, and a habit of applying real patches the day they do exist.
When a zero-day becomes a named CVE, treat internet-facing and known-exploited overlap as the front of the queue. This page does not describe how to use one.
Fact source: ASD's ACSC glossary.
