Inc Ransomware Leverages Two SonicWall SMA Zero‑Day Flaws to Gain Root Access
What Happened — The ransomware group Inc Ransomware has chained together two previously unknown (zero‑day) vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances, allowing the attackers to obtain root‑level privileges on the devices.
Why It Matters for Compliance & Audit Readiness
- Unpatched critical flaws directly violate SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) requirements for timely vulnerability remediation.
- Demonstrating continuous monitoring and evidence of patch deployment is essential to prove due diligence during an audit.
- Mapping these exploits to your control framework helps create a defensible audit trail and supports the Control Mapping capability in Verisq’s Trust Center.
Who Is Affected — Enterprises across all sectors that deploy SonicWall SMA for remote access, notably technology‑focused firms, cloud service providers, and regulated industries (finance, healthcare, government).
Recommended Actions
- Immediately verify whether your SMA appliances are running vulnerable firmware; apply SonicWall’s emergency patches as soon as they are released.
- Conduct a rapid vulnerability scan of all remote‑access devices and document remediation steps for SOC 2 evidence.
- Update your change‑management and patch‑management procedures to include zero‑day monitoring and automated evidence collection.
Source: Dark Reading
Technical Notes – The two flaws (CVE‑2025‑XXXX and CVE‑2025‑YYYY) allow remote code execution and privilege escalation, respectively, when chained. Exploitation grants attackers full system control, paving the way for ransomware deployment. Source: [Dark Reading]