Google Reports 90 Zero-Day Exploits in 2025: Enterprise Software at Risk
The Google Threat Intelligence Group (GTIG) reported 90 zero-day vulnerabilities exploited in 2025, with nearly half targeting enterprise software and appliances. This trend highlights a strategic shift by sophisticated threat actors toward high-value corporate infrastructure and edge devices.
Key Takeaways
- The Google Threat Intelligence Group (GTIG) reported 90 zero-day vulnerabilities exploited in 2025, with nearly half targeting enterprise software and appliances.
- This trend highlights a strategic shift by sophisticated threat actors toward high-value corporate infrastructure and edge devices.
Key Intelligence
Key Facts
- 190 zero-day vulnerabilities were actively exploited in the wild throughout 2025
- 2Nearly 50% of the identified exploits targeted enterprise software and appliances
- 3The data was compiled and reported by the Google Threat Intelligence Group (GTIG)
- 4Attackers are increasingly focusing on edge devices like VPNs and firewalls over consumer endpoints
- 5The report highlights a significant shift in attacker tactics toward high-value corporate infrastructure
- 6Memory safety improvements in consumer software are driving attackers toward less-mature enterprise codebases
Who's Affected
Analysis
The release of the 2025 zero-day exploitation report by the Google Threat Intelligence Group (GTIG) marks a critical inflection point in the global cybersecurity landscape. With 90 separate zero-day vulnerabilities actively exploited in the wild last year, the sheer volume of discovery highlights a threat environment that is both highly sophisticated and exceptionally well-resourced. For the SaaS and Cloud sectors, the most significant takeaway is not just the quantity of these exploits, but their specific distribution: nearly 50% of the identified zero-days targeted enterprise software and appliances, such as VPNs, firewalls, and mail servers, rather than traditional consumer-facing endpoints like browsers or mobile operating systems.
This strategic shift toward enterprise infrastructure reflects a tactical evolution among both state-sponsored actors and high-tier cybercriminal groups. By targeting edge devices and core business applications, attackers are able to gain a persistent foothold that facilitates lateral movement across corporate networks, often while bypassing traditional perimeter defenses. This 'living off the edge' strategy is particularly effective because enterprise appliances are frequently difficult to monitor and often do not support the same level of endpoint detection and response (EDR) or forensic logging as standard workstations or cloud-native workloads. The GTIG report suggests that while memory safety improvements and sandboxing in consumer software are making those targets increasingly difficult to compromise, the enterprise software ecosystem has not yet reached a comparable level of security maturity, leaving it as the path of least resistance for advanced persistent threats (APTs).
The release of the 2025 zero-day exploitation report by the Google Threat Intelligence Group (GTIG) marks a critical inflection point in the global cybersecurity landscape.
For SaaS providers and cloud infrastructure operators, the implications of this trend are profound. The infrastructure supporting modern cloud services is itself a primary target; a single zero-day in a widely used virtualization layer, identity provider, or load balancer could have catastrophic cascading effects across thousands of downstream customers. As attackers move further up the technology stack, the security of the application layer and the underlying management plane becomes the primary battleground. This necessitates a move away from reactive patching toward a 'secure by design' philosophy. SaaS vendors are under increasing pressure to demonstrate that their platforms are built on hardened, memory-safe foundations and that they maintain rigorous control over the third-party appliances and libraries integrated into their environments.
What to Watch
The geopolitical dimension of these attacks cannot be ignored. The GTIG has historically linked a significant portion of zero-day exploitation to state-sponsored hacking groups from regions including China and Iran. These actors prioritize long-term espionage and data exfiltration, making high-value corporate infrastructure an ideal target for their operations. The ability to exploit a zero-day in a perimeter device allows these groups to maintain access for months or even years before detection. This reality is forcing organizations to adopt a 'zero trust' architecture where no single device or user is inherently trusted, regardless of their location on the network.
Looking ahead to 2026, the industry should expect the volume of zero-day discoveries to remain high, potentially accelerated by the integration of generative AI into the exploit development lifecycle. While AI can help attackers identify and weaponize unknown flaws more rapidly, it also offers a powerful tool for defenders. Automated vulnerability research and AI-driven patch generation are becoming essential components of a modern defense strategy. However, the critical metric for the coming year will not just be the number of zero-days discovered, but the 'time-to-patch' across the fragmented enterprise ecosystem. Organizations must transition to a model of continuous verification and assume that their edge infrastructure is under constant scrutiny by sophisticated adversaries. The era of the 'secure perimeter' is effectively over; the future of SaaS and cloud security lies in the resilience of the individual services and the speed at which the industry can respond to the inevitable discovery of the next unknown flaw.
Cite This Page
"Google Reports 90 Zero-Day Exploits in 2025: Enterprise Software at Risk." SaaS Intelligence Brief, March 6, 2026. https://getsaasbrief.com/story/google-zero-day-report-2025-enterprise-security
How we covered this story
Every story in our saas coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the saas space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled saas-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |