A zero-day (also known as a 0-day) is a cybersecurity vulnerability in a computer system that is unknown to its developers, cybersecurity specialists, or anti-malware companies. Until the vulnerability is remedied, threat actors can exploit it in a zero-day exploit, or zero-day attack.
Vendors who discover the vulnerability may create patches or advise workarounds to mitigate it — though users need to deploy that mitigation to eliminate the vulnerability in their systems.