What should a business know about zero-day vulnerabilities?
A zero-day is a flaw exploited before a patch exists, so patching speed cannot be your only defence. The practical implication is narrow: nearly half of exploited zero-days now target enterprise technology — security appliances, VPNs and edge devices — so the priority is reducing what those devices can reach when one fails.
What the 2025 data shows
Google Threat Intelligence tracked 90 zero-day vulnerabilities exploited in the wild during 2025, up from 78 in 2024. The headline number matters less than its distribution.
- 43 of the 90 (48%) targeted enterprise technology, continuing a structural shift away from consumer platforms.
- 21 hit security and networking products — roughly half of all enterprise-facing zero-days — with 14 of those in edge devices specifically.
- Cisco, Fortinet, Ivanti and VMware featured among the most exploited enterprise vendors, alongside big-tech platforms.
- Commercial surveillance vendors exceeded traditional state-sponsored groups for the first time, and financially motivated groups accounted for nine.
Mandiant’s M-Trends 2026 puts the mean time to exploit at minus seven days — on average, exploitation precedes the patch.
The uncomfortable implication
The devices most likely to be attacked with a zero-day are the ones sitting at your perimeter doing security: the VPN concentrator, the firewall, the secure web gateway, the load balancer. They are internet-facing by design, they hold privileged network position, and they are frequently excluded from endpoint monitoring because they are appliances.
That combination is why a single edge zero-day so often becomes a full compromise. The answer is not better patching — by definition there is no patch — but limiting what a compromised appliance can do next.
Six things that work when there is no patch
1. Inventory your edge honestly
Every internet-facing appliance, its firmware version, its vendor, and who is responsible for it. Talos found exposed or vulnerable infrastructure contributing to 25% of Q1 2026 engagements. You cannot triage a vendor advisory in hours if you need two days to work out whether you run the product.
2. Subscribe to vendor advisories and the KEV catalogue
CISA’s Known Exploited Vulnerabilities catalogue is the practical shortlist of what is actually being used against people, as opposed to what merely scores highly. Wire it into your triage, not into a mailbox nobody reads.
3. Segment the appliance, not just the network behind it
Assume the edge device is compromised and ask what it can reach. A VPN concentrator that can talk to a domain controller is a different risk from one that cannot. This is the control that turns a zero-day into an incident rather than a catastrophe.
4. Monitor appliances as if they were servers
Forward their logs off-box, alert on configuration changes and unexpected outbound connections, and check integrity after every firmware update. Many edge compromises are found only because someone noticed a device calling somewhere strange.
5. Decide your emergency change path in advance
When an actively exploited flaw is published on a Friday, the constraint is rarely technical. It is authority. Agree now who can approve an out-of-band change and what testing is waived, so the decision takes minutes.
6. Reduce the attack surface you do not need
Every management interface reachable from the internet is an optional risk. Restrict administration to a jump host or a private path. The zero-day you are never exposed to is the cheapest one to handle.
Keeping perspective
Ninety zero-days a year across the whole industry is a small fraction of the vulnerabilities that will actually be used against you. Known, unpatched flaws remain the larger problem — Verizon’s 2026 DBIR puts vulnerability exploitation at 31% of breaches overall. Zero-days deserve architectural attention. They do not deserve to displace patching the flaws that already have fixes.
Where Rivo fits
Our cybersecurity services cover threat surface mapping, network segmentation, vulnerability assessment and penetration testing. Where the estate is cloud-based, our cloud services team handles the equivalent exposure at the control plane. Talk to our engineers about your edge.





