Uat-9686 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
December 17, 2025
Last Seen
January 16, 2026

Related Threat Clusters

  • Cisco Fixes Critical AsyncOS Vulnerability Under Attack

    Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…

    11 articles · Updated January 15, 2026
  • Cisco AsyncOS Zero-Day Exploited by Chinese APT Group

    A zero-day vulnerability in Cisco AsyncOS Software has been actively exploited since late November 2025. The attack targets Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute…

    2 articles · Updated December 18, 2025
  • China-linked APT UAT Exploits Cisco AsyncOS Flaw CVE-2025-20393

    Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway…

    3 articles · Updated January 16, 2026
  • Cisco Secure Email Gateway Targeted by Advanced Persistent Threat

    Cisco Talos reported that the Secure Email Gateway is under attack due to a zero-day vulnerability. The campaign is attributed to UAT-9686, an advanced persistent threat actor believed to have connections to China.…

    2 articles · Updated January 16, 2026
  • Cisco ASA Zero-Day Exploited in State-Espionage Campaign

    Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…

    27 articles · Updated December 18, 2025
  • Cisco Patches ISE Vulnerability with Public Exploit Code

    Cisco has patched a vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. The flaw, tracked as CVE-2026-20029, allows remote attackers with admin-level privileges to…

    7 articles · Updated January 8, 2026
  • Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers

    Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…

    5 articles · Updated December 17, 2025

Recent Intelligence Reports

  • Cisco Zero-Day Vulnerability Exploited: Secure Email Gateway Under Attack — Redhotcyber · January 16, 2026
  • China-linked APT UAT — Securityaffairs.Co · January 16, 2026
  • Cisco finally fixes AsyncOS zero — Bleepingcomputer · January 16, 2026
  • Cisco's Zero-Day Nightmare: China-Linked Hackers Breach Email Defenses — Webpronews · January 16, 2026
  • Cisco finally fixes max-severity bug under attack for weeks — Theregister · January 15, 2026
  • Cisco finally fixes max — Theregister · January 15, 2026
  • Cisco Releases Emergency Patch For ISE Vulnerability After Proof-of — Linkedin · January 8, 2026
  • Cisco says China — Cybersecuritydive · December 18, 2025

CVSS v3.1 Breakdown