What is a zero-day vulnerability?
A zero-day vulnerability is a flaw in software or hardware that is unknown to the vendor, who has therefore had zero days to fix it. Until a patch ships, every affected deployment is exposed, and an exploit built for the flaw works even against well-maintained systems. Zero-days are traded on grey markets and used in targeted intrusions, espionage and ransomware operations.
Disclosure, bug bounties and patching
Under coordinated (responsible) disclosure, a researcher reports the flaw privately and gives the vendor a defined window to remediate before publication. Bug bounty programmes formalise this: they pay rewards, define what may be tested, and include safe-harbour language assuring good-faith researchers that the company will not pursue them. Once a fix is published the flaw becomes an “n-day”: attackers reverse-engineer patches within days, so the speed at which customers deploy updates matters as much as the patch itself.
The legal dimension: patch SLAs in vendor contracts
For buyers, zero-days are a contract drafting problem. Well-drafted supplier and SaaS terms include a severity classification for vulnerabilities; remediation deadlines per severity tier, backed by SLA enforcement mechanics; prompt notification of vulnerabilities affecting the service; audit and testing rights; and termination or service credits for chronic failure. In the EU, the Cyber Resilience Act imposes vulnerability handling and reporting duties on manufacturers of products with digital elements, and the NIS2 Directive requires in-scope entities to manage vulnerabilities as part of their cyber risk measures.
Turkish context
Under Article 12 of the KVKK, data controllers must take technical and organisational measures appropriate to the risk; leaving a known vulnerability unpatched weighs against the controller if a breach follows, and personal data breaches must be notified to the Personal Data Protection Board within 72 hours under the Board’s established practice. Turkish law has no codified safe harbour for security research, and unauthorised access to information systems is a criminal offence under the Turkish Criminal Code, so bug bounty terms should define authorisation and scope precisely.
Do: put severity-based patch deadlines and vulnerability notification duties into every vendor contract. Don’t: rely on a vendor’s goodwill for critical fixes, or run a bounty programme without written authorisation boundaries.
Related terms
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call