VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

2026-08-06T20:52:01Z4c9a7f06263aceb5c682e9cea593f3504064f7a361777d65cdbdd35a1ad18740
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-16637CVE-2026-16771CVE-2026-8496active-exploitationarbitrary-file-overwriteauthentication-bypassbroken-object-level-authorizationcloud-deploymentcredential-disclosurecross-site-scriptingdata-exposuredefault-credentialsidorllm-servingmultiple-vulnerabilitiesnetwork-gatewayremote-code-executionserver-side-request-forgerysymlink-followingwebmail

What happened

CERT/CC vulnerability notes published July–August 2026 describe critical flaws across SOGo, VPS deployment templates, SGLang, foreUP, app-builder, OPeNDAP Hyrax, and Arris BGW210-700. Issues include unauthenticated remote code execution, active XSS exploitation, exposed/default credentials, authentication bypass, SSRF, credential and data disclosure, broken object-level authorization, and arbitrary file overwrite. Several vulnerabilities lack patches or affect internet- or LAN-exposed services; immediate remediation includes upgrading affected software, replacing default secrets, restricting4e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
4c9a7f06263aceb5c682e9cea593f3504064f7a361777d65cdbdd35a1ad18740
Enrichment time
2026-08-06T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations · Baitaphish