The Zero Day Initiative buys vulnerabilities from researchers and gives vendors a fixed window to patch before public disclosure. This is a leading signal β flaws that are confirmed but not yet public. Below: how many pre-disclosures enter the pipeline each month, which vendors are sitting on the most unpatched reports, the severity mix, and how many vendors have blown past their disclosure deadline.