Skip to content

CVE-2026-66302

Skype for Business Server remote code execution lets unauthenticated attackers run code (CVE-2026-66302)

Critical 9.8 Vendor: Microsoft Published

Critical remote code execution in Skype for Business Server can be exploited over the network without authentication. Microsoft has published fixed builds for Skype for Business Server 2015 CU13, 2019 CU8 and Subscription Edition CU1.

What happened

Microsoft describes CVE-2026-66302 as an external control of file name or path in Skype for Business Server. An attacker who can reach an affected server over the network can exploit this without authentication or user interaction to execute code, with high impact on confidentiality, integrity and availability. CVSS v3.1 rates the vulnerability critical at 9.8.

The attack is network-based, low complexity, requires no privileges and no user interaction. Microsoft has not stated whether this vulnerability has been exploited in the wild, and it is not listed in CISA KEV.

Who is affected

Affected versions are those before the fixed builds listed below. Skype for Business Server 2015 CU13: versions 9319.0 to before 6.0.9319.885. Skype for Business Server 2019 CU8: versions 2046.0 to before 7.0.2046.569. Skype for Business Server Subscription Edition CU1: versions 2046.0 to before 7.0.2046.879. These server roles are typically deployed for enterprise messaging, presence and conferencing.

What to do now

  1. Apply the update. Microsoft has published fixed builds: Skype for Business Server 2015 CU13 6.0.9319.885 (KB5123301); Skype for Business Server 2019 CU8 7.0.2046.569 (KB5123300); Skype for Business Server Subscription Edition CU1 7.0.2046.879 (KB5123287).
  2. No workaround is listed in Microsoft's advisory. Patching should be the primary remediation.
  3. If patching cannot be completed immediately, restrict network access to affected Skype for Business servers to trusted networks and administrative hosts, and monitor those hosts for unexpected activity.

How to detect it

Microsoft's advisory does not publish indicators of compromise for CVE-2026-66302. Because the vulnerability is reachable over the network without authentication, begin by identifying every Skype for Business Server role that is reachable from untrusted networks and reducing that exposure. Treat unexpected activity on these hosts as worth investigating while patching is in progress.

Beyond the patch

Apply the patch first. After that, treat this as an exposure management issue: a critical vulnerability reachable over the network without credentials is exactly what Virtual CISO Services can help you map, prioritise and close across a Microsoft estate. If exploitation does succeed, the post-exploitation activity from code execution is what Managed Detection & Response is designed to catch. Virtual CISO Services and Managed Detection & Response are the immediate supports.

Affected and fixed versions

ProductAffectedFixed in
Skype for Business Server 2015 CU139319.0 – < 6.0.9319.8856.0.9319.885
Skype for Business Server 2019 CU82046.0 – < 7.0.2046.5697.0.2046.569
Skype for Business Server Subscription Edition CU12046.0 – < 7.0.2046.8797.0.2046.879

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.