Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-66302 2026-09-08

CVE-2026-66302: Critical Skype for Business Server RCE Scores 9.8

"Microsoft disclosed a critical path-control flaw in Skype for Business Server that lets an unauthenticated remote attacker execute code, rated CVSS 9.8."

Microsoft disclosed a critical path-control flaw in Skype for Business Server that lets an unauthenticated remote attacker execute code, rated CVSS 9.8.

What Is It

CVE-2026-66302 is an external control of file name or path weakness (CWE-73) in Microsoft Skype for Business. Per Microsoft's advisory, the flaw "allows an unauthorized attacker to execute code over a network."

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst-case profile for a server-side bug: network-reachable, low attack complexity, no privileges, and no user interaction required, with high impact to confidentiality, integrity, and availability. Base score is 9.8 (CRITICAL), with an exploitability subscore of 3.9 out of a possible 3.9.

The CVE was published 2026-09-08 by Microsoft ([email protected]) and is currently listed in NVD as "Undergoing Analysis."

Why It Matters

Skype for Business Server is a network-facing collaboration platform that frequently sits at or near the edge of enterprise environments and is integrated with directory services. Remote code execution requiring no credentials and no user interaction on that class of asset is a direct path to internal footholds.

Neither Microsoft's advisory nor the NVD record reports active exploitation of CVE-2026-66302, and neither establishes its status in CISA's Known Exploited Vulnerabilities catalog. Teams that operate under KEV-driven remediation timelines should check the catalog directly rather than infer a deadline from these records.

What's Vulnerable

Microsoft lists three affected products, all on x64-based systems:

Product Fixed in
Skype for Business Server 2015 CU13 6.0.9319.885
Skype for Business Server 2019 CU8 7.0.2046.569
Skype for Business Server Subscription Edition CU1 7.0.2046.879

Builds below those versions (from base 9319.0 and 2046.0 respectively) are affected.

Patch Status

Microsoft has published fixed build numbers for all three affected products, indicating updates are available through the MSRC Update Guide. Administrators should confirm their Skype for Business Server build against the table above and update to at or above the listed fixed version. No vendor-specified workaround or mitigation appears in the supplied data.

Independent of exploitation status, the CVSS profile, unauthenticated network RCE on an edge-adjacent collaboration server, warrants treating this on an emergency patch cycle.

Sources