CVE-2026-69646: Skype for Business Spoofing Vulnerability

Overview

Severity
High (CVSS 8.3)
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

FAQ

How could an attacker exploit this vulnerability? An attacker with access to the internal network and a certificate trusted by the deployment could exploit this vulnerability by impersonating a trusted Skype for Business server. Successful exploitation could allow the attacker to act as another user or administrator without Skype credentials or user interaction.

Affected Products (3)

Microsoft Office

  • Skype for Business Server 2019 CU8
  • Skype for Business Server Subscription Edition CU1
  • Skype for Business Server 2015 CU13

Security Updates (1)

Acknowledgments

Yogesh Mandge

Revision History

  • 2026-09-08: Information published.