VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
Alinto SOGo versions prior to 5.12.8 contain an XSS flaw in how they render ICS (iCalendar) DESCRIPTION content, allowing an SVG payload with JavaScript to execute in the webmail interface and potentially expose mailbox data. The advisory identifies the issue as CVE-2026-8496.