Skip to content
Deep Analysis3 min read

GTIG Report 2026: 90 Zero-Days Exploited in 2025 — Enterprise Is the New Battlefield

9 April 2026|AEGIDA Research Team

Google Threat Intelligence Group (GTIG) published its annual review of zero-days exploited in-the-wild in 2025, revealing 90 actively exploited zero-days — up from 78 in 2024. The most significant finding: enterprise technologies represent 48% of all exploited zero-days (43 out of 90), reaching an all-time high in both absolute numbers and proportion. The 60-100 annual zero-day range has stabilized as the new normal.

The Structural Shift: From End Users to Enterprise Infrastructure

GTIG had already identified an emerging trend toward enterprise exploitation in 2024. In 2025, that trend consolidated into a structural shift. Nearly half of zero-days now target the infrastructure companies use to protect themselves: firewalls, VPN concentrators, edge routers, endpoint management platforms, and security software. These edge devices often lack EDR capabilities, creating operational blind spots that attackers exploit systematically.

In 2025, 48% of exploited zero-days targeted enterprise technology (43 of 90) — an all-time record. Edge devices (firewalls, VPNs, routers) are the primary target because they offer privileged network access with minimal detection coverage. The devices designed to protect have become the preferred entry vectors.

Surveillance Vendors Surpass Nation-States

Of 42 zero-days attributed to specific actors, commercial surveillance vendors (CSVs) were involved in 15 cases, surpassing state espionage groups (12) for the first time. Companies like NSO Group, Candiru, Intellexa and their successors continue developing and selling exploitation capabilities to governments worldwide. Zero-days developed by CSVs target journalists, activists, and dissidents — but the same vulnerabilities, once discovered or leaked, become available to state and criminal actors.

China Doubles Down: 10 Zero-Days in 2025

GTIG attributes at least 10 zero-days to China-nexus espionage groups in 2025 — double the 2024 figure. Chinese targets are predominantly edge devices and network infrastructure, suggesting a deliberate strategy: rather than hitting endpoints where EDR can detect activity, Chinese groups prefer compromising network devices that lack advanced detection and provide persistent privileged access.

Of 42 attributed zero-days in 2025: 15 to commercial surveillance vendors (CSVs), 12 to state espionage groups (10 to China alone), and the rest to cybercrime and unclassified actors. CSVs surpass nation-states for the first time — raising urgent regulatory questions about the surveillance market.

The Edge Device Paradox: Security Creating Insecurity

The GTIG report highlights a fundamental paradox: devices designed to protect corporate networks have become attackers' preferred entry vector. Reasons are structural: privileged access (a compromised firewall bypasses all perimeter defenses), limited visibility (most EDR doesn't cover edge devices), software complexity, difficult updates creating prolonged exposure windows, and strategic value (a single device can provide persistent access for months or years).

AI as Accelerator: The GTIG Perspective

The report warns that AI will become increasingly important for scaling and accelerating threat activity. Attackers will increasingly use AI for automated reconnaissance, vulnerability discovery, and exploit development. If AI can accelerate vulnerability discovery, the cost of finding new zero-days decreases — meaning more zero-days available and potentially shorter exposure windows. The WEF Global Cybersecurity Outlook 2026 corroborates this, identifying AI acceleration and geopolitical fractures as the two main cybersecurity drivers.

Key Numbers from the GTIG 2026 Report

  • 90 zero-days exploited in-the-wild in 2025 (up from 78 in 2024)
  • 43 zero-days (48%) targeted enterprise technology — all-time high
  • 15 zero-days attributed to commercial surveillance vendors (CSVs) — record
  • 12 zero-days attributed to state espionage groups
  • 10 zero-days attributed to Chinese groups — doubled from 2024
  • The 60-100 annual zero-day range has stabilized as the new normal
  • Edge devices (firewalls, VPNs, routers) are the fastest-growing target category
  • AI identified as a future accelerator for vulnerability discovery and exploitation

Implications for European Organizations

NIS2 requires organizations to adopt adequate measures for security risk management. But if nearly half of zero-days target the very enterprise technologies organizations deploy to meet these regulatory requirements, compliance itself becomes paradoxical. The answer is not to abandon security devices but to change the mental model: firewalls, VPNs, and endpoint management systems must be treated as high-risk assets, not security guarantees.

Operational Recommendations

  1. 1.Edge device inventory: map all internet-facing firewalls, VPNs, routers, and endpoint management systems. Verify firmware versions and patching status.
  2. 2.Dedicated edge device monitoring: implement specific logging for perimeter security devices. Traditional EDR doesn't cover them — use NDR and dedicated log analysis.
  3. 3.Emergency patching as standard process: with zero-days hitting edge devices at increasing frequency, implement emergency patching within 24-48 hours of disclosure.
  4. 4.Zero Trust beyond marketing: implement "never trust, always verify" even for traffic traversing security devices.
  5. 5.Threat hunting on edge devices: use GTIG and vendor IOCs to proactively search for prior compromise signs.
  6. 6.Perimeter compromise response plans: include the specific scenario "firewall/VPN compromised" in incident response plans.
  7. 7.CSV vendor assessment: for organizations in sensitive sectors, assess commercial spyware exposure and implement specific protections.
  8. 8.Monitor AI evolution in the threat landscape: understand how AI accelerates vulnerability discovery and exploit development.

Conclusion: The Perimeter Is No Longer the Wall — It's the Door

The GTIG 2026 report documents a fundamental transformation: devices designed to protect corporate networks have become the primary target of the world's most sophisticated attackers. With 43 enterprise zero-days in 2025 alone, the perimeter is no longer the wall protecting the organization — it's the door through which attackers enter. Organizations that don't adopt this mindset will find themselves compromised through the very devices they installed for protection.

Primary sources: Google Threat Intelligence Group — "Look What You Made Us Patch: 2025 Zero-Days in Review" (Google Cloud Blog, March 2026), BleepingComputer (March 2026), SecurityWeek (March 2026), Security Affairs (March 2026), Cybersecurity Dive (March 2026), The Register (March 2026), WEF Global Cybersecurity Outlook 2026.