CVE-2026-66302
Skype for Business Server remote code execution lets unauthenticated attackers run code (CVE-2026-66302)
Critical remote code execution in Skype for Business Server can be exploited over the network without authentication. Microsoft has published fixed builds for Skype for Business Server 2015 CU13, 2019 CU8 and Subscription Edition CU1.
What happened
Microsoft describes CVE-2026-66302 as an external control of file name or path in Skype for Business Server. An attacker who can reach an affected server over the network can exploit this without authentication or user interaction to execute code, with high impact on confidentiality, integrity and availability. CVSS v3.1 rates the vulnerability critical at 9.8.
The attack is network-based, low complexity, requires no privileges and no user interaction. Microsoft has not stated whether this vulnerability has been exploited in the wild, and it is not listed in CISA KEV.
Who is affected
Affected versions are those before the fixed builds listed below. Skype for Business Server 2015 CU13: versions 9319.0 to before 6.0.9319.885. Skype for Business Server 2019 CU8: versions 2046.0 to before 7.0.2046.569. Skype for Business Server Subscription Edition CU1: versions 2046.0 to before 7.0.2046.879. These server roles are typically deployed for enterprise messaging, presence and conferencing.
What to do now
- Apply the update. Microsoft has published fixed builds: Skype for Business Server 2015 CU13 6.0.9319.885 (KB5123301); Skype for Business Server 2019 CU8 7.0.2046.569 (KB5123300); Skype for Business Server Subscription Edition CU1 7.0.2046.879 (KB5123287).
- No workaround is listed in Microsoft's advisory. Patching should be the primary remediation.
- If patching cannot be completed immediately, restrict network access to affected Skype for Business servers to trusted networks and administrative hosts, and monitor those hosts for unexpected activity.
How to detect it
Microsoft's advisory does not publish indicators of compromise for CVE-2026-66302. Because the vulnerability is reachable over the network without authentication, begin by identifying every Skype for Business Server role that is reachable from untrusted networks and reducing that exposure. Treat unexpected activity on these hosts as worth investigating while patching is in progress.
Beyond the patch
Apply the patch first. After that, treat this as an exposure management issue: a critical vulnerability reachable over the network without credentials is exactly what Virtual CISO Services can help you map, prioritise and close across a Microsoft estate. If exploitation does succeed, the post-exploitation activity from code execution is what Managed Detection & Response is designed to catch. Virtual CISO Services and Managed Detection & Response are the immediate supports.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Skype for Business Server 2015 CU13 | 9319.0 – < 6.0.9319.885 | 6.0.9319.885 |
| Skype for Business Server 2019 CU8 | 2046.0 – < 7.0.2046.569 | 7.0.2046.569 |
| Skype for Business Server Subscription Edition CU1 | 2046.0 – < 7.0.2046.879 | 7.0.2046.879 |