Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-05 and was added to the RWP archive on 2026-09-07.

Daily Top · Vulnerabilities

GTIG's 2025 zero-day tally was enterprise-heavy: 90 exploited bugs, almost half in business tech

Google Threat Intelligence counted 90 in-the-wild 2025 zero-days, with 43 (48%) hitting enterprise products — a record share — and exploitation still Mandiant's top IR initial-access vector.

RWP Ventures · 2026-09-07 · event 2025-12-31 · 2 min read · priority 8.1

Bottom line up front

CONFIRMED On 5 March 2026 GTIG published its 2025 zero-day review: 90 vulnerabilities exploited in the wild. That is below 2023's 100, above 2024's 78, and inside the 60–100 band of the prior four years. The structural story is enterprise: 43 bugs, 48% of the year, both record highs. GTIG repeats that vulnerability exploitation was Mandiant IR's number-one initial access vector, ahead of stolen credentials and phishing.

This archive already covers two 2025 enterprise RCEs that match the thesis (GoAnywhere, React2Shell). Historical backfill of 5 March 2026 reporting; added 7 September 2026.

What happened

GTIG's annual count is not a CVE dump in the public HTML we used; it is a strategic cut. The defender takeaway they emphasize: prepare for when, not if. Edge and enterprise apps are where 2025's in-the-wild energy went, continuing a 2024 shift.

RWP is not inventing a top-10 CVE list GTIG did not put in the extracted summary. Use KEV plus your own internet-facing inventory as the operational list.

Why it mattered

Consumer-browser zero-days still matter for executives. They are no longer the whole budget. File-transfer, VPN, email security, and now RSC/Next are how ransomware and espionage actually walk in. A VM program that still ranks by CVSS without exposure and exploit-in-wild will miss the 48%.

Who / what was affected

Every org with internet-facing enterprise software. GTIG's 90 is a researcher census, not your scanner.

Technical context

Prioritization order that matches 2025 evidence: (1) KEV / in-the-wild, (2) internet-facing, (3) authn bypass or RCE, (4) everything else. AI-assisted discovery (other registry items) compresses the time from patch to exploit; the 2025 count staying in-band is not comfort if the mix moved to products you patch slowly.

Exploitation / threat status at the time

CONFIRMED 90 / 43 / 48% as GTIG's 2025 accounting.

ASSESSED (high): exploitation remains the IR door of first resort.

UNKNOWN how many of the 90 were unique to one victim vs mass.

What defenders should have done

  1. Re-rank the 2026 patch SLAs around internet-facing enterprise, not workstation AV.
  2. Emergency window for KEV measured in days, not the next change board.
  3. Edge-device logging that is not "send to vendor cloud and forget."
  4. Tabletop a GoAnywhere/React2Shell-class 72-hour exploit.

RWP assessment

Confidence: High on GTIG's published totals. Low on using 90 as a KPI you can reproduce internally.

Defensive actions

  1. Publish an internal "enterprise exposure" list with owners.
  2. Align KEV to that list weekly.
  3. Do not wait for the 2026 GTIG PDF to start.

Sources

  1. Google Threat Intelligence — Look What You Made Us Patch: 2025 Zero-Days in Review
  2. CISA — Known Exploited Vulnerabilities Catalog
  3. Microsoft — Defending against React2Shell CVE-2025-55182