Zero-day exploit
A vulnerability attackers know about before the vendor can ship a patch – meaning "zero days" of warning.
A zero-day exploit abuses a vulnerability before the vendor releases a patch – hence "zero days" of warning. Such flaws are traded for high prices on the underground market and are especially dangerous because traditional signature-based protection misses them.
Protection
- Behaviour-based detection (heuristics) – see ESET, Bitdefender
- Keep software and browsers up to date
- "Least privilege" principle: do not run as admin
Why this matters in 2026
Zero-day vulnerabilities trade for up to USD 2M on the underground in 2026 – the market concentrates around state actors. The risk for private users is lower but not zero: browser and PDF-reader flaws are increasingly built into mass malware as soon as they leak.
How to protect yourself
Behaviour-based detection (heuristics) instead of just signatures – top suites (ESET, Bitdefender, Kaspersky) catch unknown threats via anomalies. Plus: keep browsers and PDF readers fully patched, work under "least privilege" (no admin rights), enable sandbox features.