Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-05 and was added to the RWP archive on 2026-09-07.
GTIG's 2025 zero-day tally was enterprise-heavy: 90 exploited bugs, almost half in business tech
Google Threat Intelligence counted 90 in-the-wild 2025 zero-days, with 43 (48%) hitting enterprise products — a record share — and exploitation still Mandiant's top IR initial-access vector.
Bottom line up front
CONFIRMED On 5 March 2026 GTIG published its 2025 zero-day review: 90 vulnerabilities exploited in the wild. That is below 2023's 100, above 2024's 78, and inside the 60–100 band of the prior four years. The structural story is enterprise: 43 bugs, 48% of the year, both record highs. GTIG repeats that vulnerability exploitation was Mandiant IR's number-one initial access vector, ahead of stolen credentials and phishing.
This archive already covers two 2025 enterprise RCEs that match the thesis (GoAnywhere, React2Shell). Historical backfill of 5 March 2026 reporting; added 7 September 2026.
What happened
GTIG's annual count is not a CVE dump in the public HTML we used; it is a strategic cut. The defender takeaway they emphasize: prepare for when, not if. Edge and enterprise apps are where 2025's in-the-wild energy went, continuing a 2024 shift.
RWP is not inventing a top-10 CVE list GTIG did not put in the extracted summary. Use KEV plus your own internet-facing inventory as the operational list.
Why it mattered
Consumer-browser zero-days still matter for executives. They are no longer the whole budget. File-transfer, VPN, email security, and now RSC/Next are how ransomware and espionage actually walk in. A VM program that still ranks by CVSS without exposure and exploit-in-wild will miss the 48%.
Who / what was affected
Every org with internet-facing enterprise software. GTIG's 90 is a researcher census, not your scanner.
Technical context
Prioritization order that matches 2025 evidence: (1) KEV / in-the-wild, (2) internet-facing, (3) authn bypass or RCE, (4) everything else. AI-assisted discovery (other registry items) compresses the time from patch to exploit; the 2025 count staying in-band is not comfort if the mix moved to products you patch slowly.
Exploitation / threat status at the time
CONFIRMED 90 / 43 / 48% as GTIG's 2025 accounting.
ASSESSED (high): exploitation remains the IR door of first resort.
UNKNOWN how many of the 90 were unique to one victim vs mass.
What defenders should have done
- Re-rank the 2026 patch SLAs around internet-facing enterprise, not workstation AV.
- Emergency window for KEV measured in days, not the next change board.
- Edge-device logging that is not "send to vendor cloud and forget."
- Tabletop a GoAnywhere/React2Shell-class 72-hour exploit.
RWP assessment
Confidence: High on GTIG's published totals. Low on using 90 as a KPI you can reproduce internally.
Defensive actions
- Publish an internal "enterprise exposure" list with owners.
- Align KEV to that list weekly.
- Do not wait for the 2026 GTIG PDF to start.
Sources
- Google Threat Intelligence — Look What You Made Us Patch: 2025 Zero-Days in Review
- CISA — Known Exploited Vulnerabilities Catalog
- Microsoft — Defending against React2Shell CVE-2025-55182