← Back to Feed
Inc Ransomware Exploits SonicWall SMA Zero-Days
July 17, 2026 · Dark Reading · Severity: CRITICAL
The Inc ransomware operation exploited two zero-day vulnerabilities in SonicWall SMA (Secure Mobile Access) appliances, chaining them together to gain root-level access to affected devices. The two vulnerabilities — one providing initial access and the other enabling privilege escalation — allowed the threat actors to bypass authentication, execute arbitrary code, and establish persistence at the highest privilege level on the SMA appliances. Since SMA appliances are perimeter devices providing remote access to internal networks, compromise gives attackers a direct path into the organization's internal infrastructure, bypassing most perimeter defenses.
Key Takeaways
- Inc ransomware exploited two chained SonicWall SMA zero-days to gain root access to perimeter appliances.
- The two vulnerabilities provided initial access and privilege escalation in sequence, enabling full device compromise.
- SMA appliances sit at the network perimeter providing remote access, making compromise an open door to internal networks.