How it works
A zero-day vulnerability is a security weakness that becomes a concern before the defender has an established fix available or the relevant parties know how to address it. A vulnerability is the weakness; an exploit is a method that uses it. Disclosure, exploitation and patch availability are distinct events.
A practical example
A manufacturer might issue an advisory about a flaw while preparing a corrected release. Owners of affected versions could need a temporary mitigation during that interval. Once a fix exists, an unpatched device can remain vulnerable even though the issue is no longer treated as an unknown zero-day.
What to check
Confirm the exact product, version and configuration against the manufacturer’s advisory. Follow its recommended mitigation and track the corrected release rather than applying a workaround for a different product. Keep an inventory so affected devices can be found quickly, and verify whether the mitigation was actually applied.
Limits and safe use
The label does not mean every device has been attacked or that antivirus detects every possible exploit. A patch announcement also does not prove a previous intrusion is absent. If signs of compromise exist, assessment and recovery are separate from updating. Security reports should explain affected conditions rather than relying on the alarming name alone.