Awareness

Why Modern Apps Drive More Zero-Day Risks

Published  ·  6 min read

Modern software applications continue to fuel a significant increase in zero-day vulnerabilities and their associated exploitation. Zero-day vulnerabilities are defects or flaws that Microsoft or other software vendors are often not aware of, but can lead to significant security-related impacts. Attacks leveraging zero-day vulnerabilities have seen their weaponization accelerate at a much higher rate than they have in the past. 

In 2025 alone, the reported number of zero-day exploits has increased by 46% over the previous half; record numbers of actively exploited zero-days have been patched by Microsoft; and there are projections that the overall number of CVEs will exceed 50,000 to 59,000 in 2026 (as per FIRST predictions).

The underlying problem that is prevalent with modern app design, development, and deployment is that they provide attackers with increased opportunities to find hidden flaws; shorten the time between the discovery and exploitation of those flaws; and thus have a broader consequence for all apps in the environment.

Big Trend Factors
1. Heightened complexity, which results from the amount of dependencies placed on software. Applications now rely on multiple layers of technology. These layers include frameworks (e.g., React, Next.js, and Node.js), open-source libraries, microservices, container technologies, APIs, and cloud-native technologies. As a result of this increase in the amount of technology dependencies, there is a corresponding increase in the bugs that may be present in those applications. 

Additionally, this creates a risk for enterprises, as thousands of enterprise applications could be affected if one of the libraries or frameworks becomes vulnerable in the supply chain. In 2025, research stated that more than 60 percent of zero-days geared towards enterprise applications on those technologies (i.e., security appliances, ERP applications such as Oracle E-Business Suite, file transfer tools) were targeted by attackers (Source: Google Threat Intelligence). As shown by React2Shell (CVE-2025-55182), vulnerabilities at the framework level of technology provide attackers with the ability to create Remote Code Execution (RCE) at the web scale.

2. Rapid release cycles which place pressure on development teams to release code in an agile/DevOps manner. As a result, teams are deploying code on a daily or weekly basis and prioritizing speed over completeness of security testing before code is released. Many application releases contain latent bugs that, if exploited after release, become zero-days. 

Also, cloud-native applications have dynamic configuration files (Kubernetes and serverless) that introduce logic errors or may be misconfigured and can be exploited before those issues can be resolved. The speed at which attackers have been able to weaponize code is growing; for example, in the first half of 2025, 32.1 percent of known exploited vulnerabilities (KEVs) had evidence that they had been weaponized on the day (i.e., before) that the CVE number was assigned (VulnCheck). For comparison, that percentage was only 23.6 percent in 2024. In addition, attackers have learned to reverse-engineer security patches much more quickly, therefore increasing the potential window for an attack.

3. Mobile Devices and Ecosystems that are Fragmented and Limited in Support Duration are High Risk. In mobile devices, the lifecycle of most applications is very short (1-5 years) and manufacturers continue to create multiple versions of the Operating System (especially Android), which makes it very easy for hackers to compromise the device with a zero-day, e.g. Qualcomm/Adreno GPU vulnerabilities to either attack or steal personal information. 

Qualcomm chipsets and Android vulnerabilities were often found and exploited frequently in 2025. The spyware “ZeroDayRAT” also targeted both Android and iOS devices.

4. Enterprises and Third Party Software are Attractive to Attackers. Because they are widely deployed, attack tools are also highly scalable since exploiting just one zero-day can affect millions. Nation-states will prioritize high payout tools (extortions/ransoms) as do bad actors. 

According to VulnCheck, as of 2025, 41% of KEVs were zero-day vulnerabilities and were exhibited as enterprise platforms and exploited. As an example, Clop exploited Oracle EBS zero-day vulnerabilities in order to extort enterprises for money; Microsoft also issued multiple zero-day vulnerability patches for Office and Windows applications that were being exploited as well.

5. New vulnerabilities are being created, at an ever increasing rate, by the use of automation tools that reduce the number of days it takes from finding a vulnerability through to producing an exploit for it.  As such, particularly in the case of zero-day exploits (exploits of previously unknown software vulnerabilities), there is a strong incentive for criminals to exploit these opportunities within short timeframes in order to sell these exploits at high prices on the dark web.

Many more financial actors emerged in 2025, typically chaining multiple zero-days together for ransomware or data theft.

Data Snapshot for 2025-2026
1. In the first half of 2025, zero-day exploits have increased by 46% (source: ForeScout).
2. Microsoft identified 41 zero-days in 2025 (source: Tenable); while the highest monthly number of exploited zero-days was 6 in February (2026) on Patch Tuesday.
3. 2025 had more than 30,000 publically disclosed vulnerabilities (source: SentinelOne) with an estimate of approximately 50,000 to 59,000 CVEs at the close of 2026 (source: FIRST).
4. 32.1% of KEVs were exploited prior to or on the day they were made public (source: VulnCheck for the 1st half of 2025).
5. Enterprise/security products made up the bulk of targeted cases (>60%) (source: Google).

Practical Mitigation in Today's Environment
1. Immediate action (patching or auto update) for applications and Operating System (OS) will be prioritized. This includes both enterprise and third party applications/tools.
2. Reduce Surface; Least Privilege Access, Zero Trust, and Micro Segmentation are necessary.
3. Layer Defense Strategies: behavioral-based EDR, exploit mitigation strategies (e.g., ASLR/DEP), and web filtering/monitoring solutions.
4. Continuously Monitor Threat Intelligence Feeds to identify Emerging Zero Day Exploits; Develop Rapid Respond Playbooks.
5. A secure supply chain will require SBOM (software bill of materials), vendor vetting, and dependency scanning.
6. Mobile Device Security: No sideloading, enforcement of MDM policy, and immediate updates.

Modern applications are built with rapid innovation; however, at the same time, they are increasingly complex and rapid in terms of how quickly an attacker can exploit them. This trend is only likely to continue to grow as zero-day vulnerabilities are developed. Therefore, focusing on speed, visibility, and layered controls is critical to managing risk.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067