CVE-2026-66302: Skype for Business Remote Code Execution Vulnerability

Overview

Severity
Critical (CVSS 9.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08
EPSS Score
0.54% (percentile: 43.9%)

Description

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit this vulnerability over the network by sending a specially crafted request that writes an attacker-controlled file to an arbitrary location on the affected server. Successful exploitation could result in the attacker executing code on the target server. No authentication or user interaction is required.

Affected Products (3)

Microsoft Office

  • Skype for Business Server 2019 CU8
  • Skype for Business Server Subscription Edition CU1
  • Skype for Business Server 2015 CU13

Security Updates (1)

Acknowledgments

odgrso with <a href="https://gmo-cybersecurity.com/">GMO CyberSecurity by Ierae</a>, Manish Kumar, Nitish Kumar

Revision History

  • 2026-09-08: Information published.