Zero-day
A vulnerability being exploited before the vendor has released a fix, leaving no patch available.
The name refers to the number of days the vendor has had to respond. Genuine zero-days are relatively rare and usually aimed at high-value targets, though once disclosed they are adopted broadly and quickly.
Because patching is not an option at the moment of disclosure, the response relies on layered controls: reducing exposure, applying vendor workarounds, and having detection that would notice exploitation rather than just the vulnerability.
Where this comes up
Zero-day sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.