Microsoft Skype For Business Server — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Skype For Business Server, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (24)
CVE-2026-66302 — CVSS 9.8 (critical): External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-69646 — CVSS 8.3 (high): Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent…
CVE-2026-66304 — CVSS 7.5 (high): Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66307 — CVSS 7.5 (high): Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
CVE-2026-66305 — CVSS 7.1 (high): Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
CVE-2026-66306 — CVSS 6.5 (medium): Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information…
CVE-2026-69642 — CVSS 6.5 (medium): Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker…
CVE-2026-63523 — CVSS 6.5 (medium): Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker…
CVE-2026-66303 — CVSS 6.5 (medium): Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2019-0798 — CVSS 6.1 (medium): A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka…
CVE-2015-2531 — CVSS 4.3 (medium): Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows…
CVE-2015-2536 — CVSS 4.3 (medium): Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject…