skype_for_business_server vulnerabilities
CVEs whose affected-version data names the skype_for_business_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-66308Medium· 6.5Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-66304High· 7.5Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66302Critical· 9.8External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-69646High· 8.3Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-69642Medium· 6.5Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66307High· 7.5Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
CVE-2026-66305High· 7.1Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
CVE-2026-66303Medium· 6.5Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-63523Medium· 6.5Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66306Medium· 6.5Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.