I’ve spent close to 30 years hacking things and helping companies defend them, and in that time no security term has lost more of its meaning than “zero-day” (except maybe for the word “hacker.”) Reporters attach zero-day to nearly any high-profile vulnerability (CVE) in the news. Vendors print it in pitch decks because it sells. All that loose usage makes zero-days look common, and it hides what adversaries actually did and what defenders could have done about it.
When I came up in this industry, the term was used to mean something far more specific: a vulnerability exploited in the wild before the software vendor shipped a patch. Defenders had “0” days to respond (i.e. patch), hence the name.
Following any breach, an important thing I want to know is whether a patch existed before that breach. If an IT team had a patch available and never installed it, this points to a potential operational failure, and operational failures have operational fixes. When no patch existed, a zero-day, the team couldn’t have patched its way out at any speed. It lived or died on the controls it already had in place.
When reporters and vendors stretch “zero-day” over both situations, a security leader reading the headline can’t tell which problem they actually have.
At Root Evidence, we traced thousands of in-the-wild exploitations of published CVEs from January 1, 2018 through July 15, 2026 and checked each one against that practitioner definition.
We found that 253,912 CVEs were published during that window. Adversaries exploited 3,769 (about 1.5%) of them in the wild. The other 98.5% had no confirmed in-the-wild exploitation in our dataset. Adversaries exploited 711 before a patch existed. That’s just 0.28% of all CVEs published over 8.5 years.
Roughly one exploited CVE in five is a true zero-day, and that share has stayed between 15% and 26% every year since 2021. So far in 2026, it’s at the low end of that range, projected to be roughly 131 true zero-days (13.5%) compared with 2025’s record of 143 (17.5%). Many “experts” have predicted AI would produce a surge in zero-days; however, as of July 2026, the data shows no such surge.
If you’ve seen a chart this year claiming most exploited vulnerabilities are zero-days and time-to-exploit was speeding up to hours or minutes, there’s a good chance it came from ZeroDayClock (ZDC).
Before ZDC retired those charts in September, the day after we released our research, its methodology counted a CVE as a zero-day when exploitation was recorded on or before the day the vulnerability was published. What I want to know is: did defenders have a patch available?
If an adversary exploits a vulnerability several days after the vendor ships a patch, that’s not a zero-day under the practitioner definition the industry has used for decades. Defenders had time to patch. Whether NVD or the CVE record had been published yet doesn’t change that. This distinction is vitally important.
We ran ZDC’s rule over our own 3,769 exploited CVEs, and it classified 1,243 (about one-third), as zero-days. So we did the much harder work of collecting vendor patch dates and applied the practitioner definition to the same CVEs. We found 711 true zero-days. The difference was 532 CVEs that ZDC classified as zero-days even though a vendor fix existed before the recorded exploitation. Does that sound like a zero-day to you? It didn’t to us.
Collecting those patch dates at scale is painstaking. Patch dates have to be collected and stitched together from vendor advisories and multiple other sources. The data isn’t perfect, there are holes in it because there is no single clean database to query, but it's the best data available since much was not recorded at the time. That’s the fundamental difference between the two measurements. ZDC was measuring exploitation relative to publication. We’re measuring exploitation relative to the earliest date we know of when defenders actually had a patch available.
Before anyone quotes our 711 as gospel, I’ll point out the asterisk myself: 208 of them (or 29%), are WordPress plugin flaws. Wordfence and Patchstack have visibility across millions of WordPress sites, which gives them an unusual ability to catch adversaries exploiting plugin vulnerabilities, coordinate fixes with plugin authors, and publish disclosures and patches quickly. Those adversaries really did strike before a patch existed, so they count as true zero-days. But many involve the same kinds of relatively inexpensive web attacks criminals use every day.
Set WordPress plugins aside, and adversaries exploited 503 true zero-days across the rest of our dataset in 8.5 years. And they concentrated heavily on the same few vendors: WordPress plugins plus Microsoft, Apple, Google, Cisco, and Fortinet account for 66% of the total. There’s a good reason adversaries usually don’t need zero-days.
A zero-day requires finding or acquiring a vulnerability before a patch exists and developing an exploit that works against a useful target. That generally costs more time, skill, or money than exploiting a vulnerability everyone already knows about. And using a zero-day can burn the investment if a defender catches it and the vendor patches the flaw.
Meanwhile, an n-day can get an adversary the same access at a fraction of the cost. The vulnerability is already known, a patch can provide clues about the flaw, and exploit code may already exist. And enough organizations leave systems unpatched long enough to make old vulnerabilities useful. The data reflects that economics. Four out of five CVEs adversaries exploited since 2018 already had a patch available when exploitation began.
Which brings me back to the people concerned about AI. For the last two years, we’ve heard predictions of a mountain of exploited zero-days: machine-found flaws, weaponized in hours, by adversaries with no particular skill. We went through 8.5 years of confirmed exploitation to establish the baseline, then looked closely at what changed as AI took off.
So where are the zero-days?
Maybe at some point, evidence of AI-driven vulnerability exploitation at scale will show up clearly in the threat landscape. If and when it does, I’ll follow the data as always. Currently, the data shows that adversaries are not using AI-driven exploitation at scale. And there’s another market worth watching for signals: cyber insurance.
Cyber insurers bet real dollars on breach losses. When ransomware losses surged around 2020, insurers responded with major price increases, tighter underwriting, and reduced coverage.
Today, with the Vulnpocalypse supposedly upon us, Marsh reports twelve straight quarters of declining global cyber insurance rates. In Q2 2026 alone, global cyber rates fell another 4%. Insurer competition and available capacity are part of the reason, so falling prices alone don’t prove cyber risk is falling. But insurers aren’t behaving as though AI has suddenly created a massive new wave of losses either. That’s telling.
To me, much of the Vulnpocalypse remains “possibility” being presented as “probability.” AI absolutely could change adversary economics. The strongest AI tools are still young, and in our Vulnpocalypse Report, we identify exactly where that acceleration should show up first. Until then, I’d rather plan around the adversaries on the record than the adversaries we can imagine. It’s better to be accurate than alarming.
There is so much more to be said on this topic. I hope you will join Robert “RSnake” Hansen and me for our next webinar on September 30 at 9:00a PT, as we plan to discuss where attacks are actually coming from. Reserve your seat here.