Zero-day software vulnerabilities—security holes that developers haven’t fixed or aren’t aware of—can lurk undetected for years. They are useful in cyber operations and in defensive and academic settings. Whether to disclose or stockpile them is an ongoing debate.

Source: Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits | RAND