An n-day vulnerability is a flaw the vendor already knows about and has usually fixed. The “n” counts the days since disclosure. The danger sits in the gap between a patch being published and that patch being installed everywhere, because every unpatched system is still open to the same attack.
Most breaches that start with a software flaw use n-days rather than zero-days, since they are cheaper to exploit. The patch itself helps the attacker: the changed code shows where the flaw was and what triggers it. Turning that into a working exploit used to take a skilled researcher days or weeks, which is the window most patching policies and risk acceptances were built around.
That window has shrunk. In June 2026 Anthropic reported a model turning public Firefox patches into a working exploit in under an hour, and argued that “N-hour” now describes the problem better than “N-day”. A patch policy measured in weeks now needs a reason, written down, for each system it leaves open.