Inc Ransomware's chain against SonicWall's SMA appliances doesn't need a zero-day headline to be the story. Two vulnerabilities, used together, hand the operator root on the mobile access gateway, which means the authentication layer the appliance exists to enforce becomes irrelevant the moment both bugs fire in sequence. SonicWall's advisory language treats this as a vulnerability disclosure. The exploitation chain treats the SMA as a pivot point sitting directly on the perimeter, root-level, with no MFA prompt positioned anywhere in the path an attacker actually walks.
The pattern matters more than the vendor. SMA appliances get deployed precisely because they sit outside the corporate network boundary, brokering remote access so internal systems don't have to. Root on the box collapses that boundary function entirely, and the fix is not a patch cycle measured in weeks. It's pulling internet-facing SMA management interfaces off the public internet now, then patching, in that order. Organizations that patch first and restrict access second are solving the vulnerability while leaving the exploitation window open for however long the update takes to roll out.