What Makes a Vulnerability a 'Zero-Day' and Why the Patch Window Matters

A zero-day vulnerability is a security flaw that attackers discover and exploit before the software vendor has released a fix. The name comes from the fact that developers have had zero days to patch the issue once it becomes known to be actively exploited. That gap between discovery and patch, sometimes hours, sometimes weeks, is exactly when attackers do the most damage, because defenders don't yet know what to look for or how to block it.

For UK businesses, this timing problem is the whole story. Once a vendor issues a patch, the vulnerability stops being a zero-day and becomes a known, fixable risk. The organizations that get hurt are usually the ones that either didn't know a patch existed or hadn't applied it yet. Recent incidents make this concrete: the Windows zero-day tracked as CVE-2026-68820 was being actively exploited before a fix was widely deployed, giving attackers a real window to act while defenders scrambled to catch up.

What a VPN Can and Can't Do During a Zero-Day Exploit

This is where a lot of confusion sets in. A VPN encrypts the connection between your device and the internet, and it hides your IP address from the sites and services you connect to. That's genuinely useful for protecting data in transit, avoiding surveillance on public Wi-Fi, and adding a layer of privacy to your browsing.

But a VPN does nothing to patch a flaw in your operating system, your email server, or your printing software. If the vulnerability lives inside the application itself, encrypting the network traffic around it doesn't close the hole. An attacker exploiting an unpatched flaw in, say, a print management platform or an email server doesn't need to intercept your traffic; they just need the software to be vulnerable and reachable. A VPN protects the pipe, not the software running at either end of it.

This distinction matters because it's easy to assume a VPN subscription equals comprehensive protection. It doesn't. It's one layer among many, and understanding where that layer starts and stops is the first step toward building a defense that actually holds up.

Real-World Zero-Days That Show the Limits of Any Single Defense

Recent cases illustrate why no single tool, VPN or otherwise, can substitute for patching and monitoring. The PaperCut zero-day forced an emergency patch after researchers confirmed active exploitation of the print management software used across schools, businesses, and government agencies. Around the same time, the group known as Laundry Bear was caught exploiting a previously unknown flaw in Microsoft Exchange's Outlook Web Access to conduct espionage, and a separate Windows zero-day was leveraged by North Korean-linked hackers in targeted attacks.

None of these incidents involved a VPN failure. They involved software flaws that existed regardless of how the victim connected to the internet. A VPN running in the background wouldn't have stopped an attacker from reaching an exposed, unpatched server or exploiting a flaw in a locally installed application. These cases are a reminder that attackers go after whatever door is unlocked, and increasingly that door is a specific piece of software rather than the network connection itself.

Building a Defense-in-Depth Approach

The practical takeaway for UK businesses is that no single control, including a VPN, can substitute for a layered strategy. That strategy should include prompt patch management so fixes get applied as soon as vendors release them, continuous monitoring to catch exploitation attempts even before a patch exists, network segmentation to limit how far an attacker can move if they get in, and a VPN used specifically for what it does well: securing remote access and protecting data in transit.

The scale of the problem underscores why this matters. According to the Identity Theft Resource Center's 2026 H1 breach report, data breach victim counts have already climbed past hundreds of millions this year alone, and unpatched software flaws are a recurring theme behind many of these incidents.

What This Means For You

If you run a business or manage IT for one, treat zero-day vulnerabilities as a patching and monitoring problem first, and a network security problem second. Keep software inventories current, subscribe to vendor security advisories, and prioritize patches for internet-facing systems. Use a VPN for what it's designed to do: securing remote connections and protecting privacy, not as a substitute for updates.

Key Takeaways

  • A zero-day vulnerability VPN protection strategy only makes sense as part of a broader plan; a VPN cannot patch vulnerable software.
  • Patch promptly and monitor for exploitation, since the danger window closes once fixes are applied and deployed.
  • Real incidents involving Windows, Exchange, and print management software show attackers target software flaws directly, regardless of network encryption.
  • Combine patch management, monitoring, segmentation, and VPN use for genuine defense-in-depth rather than relying on any single tool.