Google’s Threat Intelligence Group (GTIG) reported on March 5, 2026, that 90 zero-day vulnerabilities were exploited in the wild throughout 2025.
This figure marks a 15% increase from 2024, when 78 zero-days were tracked, but remains lower than the record high of 100 seen in 2023.
Key Findings from the 2025 Report:
- Enterprise Shift: For the first time, nearly half of all exploited zero-days (43 out of 90) targeted enterprise products, such as security appliances, VPNs, and networking infrastructure.
- Primary Targets: Microsoft was the most targeted vendor with 25 zero-days, followed by Google (11) and Apple (8).
- Threat Actors:
- Commercial Surveillance Vendors (CSVs): Attributed to 18 zero-days, primarily targeting mobile devices and browsers.
- State-Sponsored Groups: Attributed to 15 zero-days, with actors from China, Russia, and the UAE focusing on “edge” devices like routers and firewalls.
- Technical Trends: Memory safety issues accounted for 35% of all exploited vulnerabilities last year.