# UNC6586

> As of 2026-08-05, UNC6586 is a threat actor tracked by Threadlinqs Intelligence across 1 threat spanning vulnerability.

- **Tracked threats:** 1
- **Categories:** VULNERABILITY
- **As of:** 2026-08-05

## Tracked threats

- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH

## Related CVEs

9 CVEs referenced by tracked UNC6586 activity.

- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-34486](https://intel.threadlinqs.com/cve/CVE-2026-34486)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-29146](https://intel.threadlinqs.com/cve/CVE-2026-29146)
- [CVE-2026-21858](https://intel.threadlinqs.com/cve/CVE-2026-21858)
- [CVE-2025-68613](https://intel.threadlinqs.com/cve/CVE-2025-68613)
- [CVE-2022-26134](https://intel.threadlinqs.com/cve/CVE-2022-26134)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC6586
