VulnSea

skype_for_business_server vulnerabilities

CVEs whose affected-version data names the skype_for_business_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-66308Medium· 6.5
1w ago

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Sunlitmicrosoft · skype_for_business_serverEPSS 0.61%via NVD
CVE-2026-66304High· 7.5
1w ago

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Twilightmicrosoft · skype_for_business_serverEPSS 0.70%via NVD
CVE-2026-66302Critical· 9.8
1w ago

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · skype_for_business_serverEPSS 0.53%via NVD
CVE-2026-69646High· 8.3
1w ago

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Twilightmicrosoft · skype_for_business_serverEPSS 0.21%via NVD
CVE-2026-69642Medium· 6.5
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sunlitmicrosoft · skype_for_business_serverEPSS 0.24%via NVD
CVE-2026-66307High· 7.5
1w ago

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · skype_for_business_serverEPSS 0.63%via NVD
CVE-2026-66305High· 7.1
1w ago

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Twilightmicrosoft · skype_for_business_serverEPSS 0.30%via NVD
CVE-2026-66303Medium· 6.5
1w ago

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Sunlitmicrosoft · skype_for_business_serverEPSS 0.79%via NVD
CVE-2026-63523Medium· 6.5
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sunlitmicrosoft · skype_for_business_serverEPSS 0.39%via NVD
CVE-2026-66306Medium· 6.5
1w ago

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · skype_for_business_serverEPSS 0.50%via NVD
skype_for_business_server vulnerabilities (CVEs) · VulnSea