CVE-2026-8496Patch

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event handler, is insufficiently sanitized before being rendered in the webmail interface. A remote attacker can execute JavaScript in the victim's browser when the malicious calendar invite is viewed. Successful exploitation may allow mailbox access, email and contact theft, session hijacking, and other actions allowed by an authenticated user.

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-13); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-13: 1Mentions · 2026-08-06: 1Mentions · 2026-09-18: 1Mentions · 2026-09-20: 1Active Exploitation · 2026-08-06: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-09-18: 1Patch / Workaround · 2026-09-20: 1Technical Details · 2026-05-13: 1Technical Details · 2026-08-06: 1Technical Details · 2026-09-18: 1Technical Details · 2026-09-20: 105-1308-0609-1809-20
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-08-061
Active Exploitation1
2026-09-181
Patch1
2026-09-201
Patch1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    【注意】SOGoのICS招待にXSS脆弱性、5.12.8へ更新を https://www.cybernote.click/2026/09/13/alinto-sogo-cve-2026-8496-ics-xss/ #IT #Security #cybersecurity

    Post summary

    The text announces a XSS vulnerability (CVE-2026-8496) in SOGo's ICS invitations and recommends updating to version 5.12.8 to remediate the issue. No PoC, exploit tool, or active exploitation claims are made.

    0000050
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    【注意】SOGoのICS招待にXSS脆弱性、5.12.8へ更新を https://www.cybernote.click/2026/09/13/alinto-sogo-cve-2026-8496-ics-xss/ #IT #Security #cybersecurity

    Post summary

    The tweet announces an XSS vulnerability in SOGo and references an update to version 5.12.8 as remediation, indicating a patch is available. No active exploitation or PoC code is mentioned.

    0000048
    207 followersView on X
  • OJOBIT@0J0BIT
    Active Exploitation

    CVE-2026-8496 is a live XSS in Alinto SOGo v5.12.7: malformed ICS calendar invites render SVG with JavaScript in the DESCRIPTION field, with no sanitization or CSP, and trigger on normal calendar view > one malformed ICS invite can execute JavaScript in SOGo v5.12.7's calendar view, giving attackers full read access to victims' mailboxes; v5.12.8 fixes it > attackers are already exploiting a live XSS vulnerability in Alinto SOGo v5.12.7, CVE-2026-8496, delivered through malformed ICS calendar invitations, and CERT/CC's > patch is already out: upgrade to Alinto SOGo v5.12.8 or newer > v5.12.8 sanitizes ICS DESCRIPTION content and tightens handling of embedded SVG and HTML > public disclosure and first publication both landed on 2026-08-06, so this is not a dormant bug report > its calendar module renders ICS DESCRIPTION fields without sanitization or Content Security Policy enforcement, which turns a crafted calendar invite into a script https://news.ojobit.com/story/actively-exploited-sogo-xss-ics-mailbox-theft-0fe0da

    Post summary

    CVE-2026-8496 is a live XSS flaw in Alinto SOGo v5.12.7 that is currently being exploited via malformed calendar invites, with a fix released in v5.12.8.

    0000074
    11 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8496 Cross-Site Scripting Vulnerability in Alinto SOGo 5.12.7 ICS Calendar Invitations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8496

    Post summary

    The text announces CVE‑2026‑8496 as a cross‑site scripting error in Alinto SOGo 5.12.7, providing only a reference link without additional exploit or mitigation details.

    0000048
    4.0K followersView on X

Explore more