VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
2026-08-06T20:52:01Z•4c9a7f06263aceb5c682e9cea593f3504064f7a361777d65cdbdd35a1ad18740
CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-16637CVE-2026-16771CVE-2026-8496active-exploitationarbitrary-file-overwriteauthentication-bypassbroken-object-level-authorizationcloud-deploymentcredential-disclosurecross-site-scriptingdata-exposuredefault-credentialsidorllm-servingmultiple-vulnerabilitiesnetwork-gatewayremote-code-executionserver-side-request-forgerysymlink-followingwebmail
What happened
CERT/CC vulnerability notes published July–August 2026 describe critical flaws across SOGo, VPS deployment templates, SGLang, foreUP, app-builder, OPeNDAP Hyrax, and Arris BGW210-700. Issues include unauthenticated remote code execution, active XSS exploitation, exposed/default credentials, authentication bypass, SSRF, credential and data disclosure, broken object-level authorization, and arbitrary file overwrite. Several vulnerabilities lack patches or affect internet- or LAN-exposed services; immediate remediation includes upgrading affected software, replacing default secrets, restricting4e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 4c9a7f06263aceb5c682e9cea593f3504064f7a361777d65cdbdd35a1ad18740
- Enrichment time
- 2026-08-06T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.