Server-Side Request Forgery in Skype for Business by Microsoft
CVE-2026-66304

7.5HIGH

What is CVE-2026-66304?

A security flaw in Skype for Business can be exploited through a server-side request forgery (SSRF) attack, allowing unauthorized users to access sensitive network information. This vulnerability poses a risk to organizations that utilize Skype for Business for communication and collaboration, as it could lead to potential data breaches or unauthorized access to internal resources. Organizations are urged to review their systems and apply relevant updates to mitigate these risks.

Affected Version(s)

Skype for Business Server 2015 CU13 x64-based Systems 9319.0 < 6.0.9319.885

Skype for Business Server 2019 CU8 x64-based Systems 2046.0 < 7.0.2046.569

Skype for Business Server Subscription Edition CU1 x64-based Systems 2046.0 < 7.0.2046.879

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.