Active Exploitation
CVE-2026-8496 is a live XSS in Alinto SOGo v5.12.7: malformed ICS calendar invites render SVG with JavaScript in the DESCRIPTION field, with no sanitization or CSP, and trigger on normal calendar view
> one malformed ICS invite can execute JavaScript in SOGo v5.12.7's calendar view, giving attackers full read access to victims' mailboxes; v5.12.8 fixes it
> attackers are already exploiting a live XSS vulnerability in Alinto SOGo v5.12.7, CVE-2026-8496, delivered through malformed ICS calendar invitations, and CERT/CC's
> patch is already out: upgrade to Alinto SOGo v5.12.8 or newer
> v5.12.8 sanitizes ICS DESCRIPTION content and tightens handling of embedded SVG and HTML
> public disclosure and first publication both landed on 2026-08-06, so this is not a dormant bug report
> its calendar module renders ICS DESCRIPTION fields without sanitization or Content Security Policy enforcement, which turns a crafted calendar invite into a script
https://news.ojobit.com/story/actively-exploited-sogo-xss-ics-mailbox-theft-0fe0da
Post summary
CVE-2026-8496 is a live XSS flaw in Alinto SOGo v5.12.7 that is currently being exploited via malformed calendar invites, with a fix released in v5.12.8.