Server-Side Request Forgery in Skype for Business by Microsoft
CVE-2026-66304
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-66304?
A security flaw in Skype for Business can be exploited through a server-side request forgery (SSRF) attack, allowing unauthorized users to access sensitive network information. This vulnerability poses a risk to organizations that utilize Skype for Business for communication and collaboration, as it could lead to potential data breaches or unauthorized access to internal resources. Organizations are urged to review their systems and apply relevant updates to mitigate these risks.
Affected Version(s)
Skype for Business Server 2015 CU13 x64-based Systems 9319.0 < 6.0.9319.885
Skype for Business Server 2019 CU8 x64-based Systems 2046.0 < 7.0.2046.569
Skype for Business Server Subscription Edition CU1 x64-based Systems 2046.0 < 7.0.2046.879