DIRAS TAKE
Treat this as high priority because the flaw allows unauthenticated remote code execution against Skype for Business Server. Prioritize patching servers reachable from untrusted networks and apply vendor updates immediately.
What is CVE-2026-66302?
An unauthenticated remote attacker can execute arbitrary code on Skype for Business Server using crafted input that controls a file name or path, tracked as CVE-2026-66302. Affected products include Skype for Business Server 2015 CU13 (6.0.9319.0 through before 6.0.9319.885), Skype for Business Server 2019 CU8 (7.0.2046.0 through before 7.0.2046.569) and Skype for Business Server Subscription Edition CU1 (7.0.2046.0 through before 7.0.2046.879). Exploitation requires only network access; no valid account or user interaction is required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Skype for Business Server 2015 CU13 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Skype for Business Server 2015 CU13 6.x | 9319.0 – before 6.0.9319.885 | 6.0.9319.885 |
| Skype for Business Server 2019 CU8 7.x | 2046.0 – before 7.0.2046.569 | 7.0.2046.569 |
| Skype for Business Server Subscription Edition CU1 7.x | 2046.0 – before 7.0.2046.879 | 7.0.2046.879 |
Is CVE-2026-66302 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-66302
- Apply the vendor updates that include the fixes: 6.0.9319.885 for Skype for Business Server 2015 CU13, 7.0.2046.569 for Skype for Business Server 2019 CU8, or 7.0.2046.879 for Skype for Business Server Subscription Edition CU1.
- Restrict network exposure for Skype for Business Server instances to trusted networks and block unnecessary public access.
- Monitor server and network logs for unusual activity and indicators of compromise related to Skype for Business Server.
- Follow Microsoft’s guidance and verify successful deployment and restart of affected services after installing updates.
Frequently asked questions
Is CVE-2026-66302 being actively exploited?
There are no public reports of exploitation of CVE-2026-66302 as of 2026-09-30.
Which Skype for Business Server versions are affected by CVE-2026-66302?
Skype for Business Server 2015 CU13 (versions 6.0.9319.0 through before 6.0.9319.885), Skype for Business Server 2019 CU8 (7.0.2046.0 through before 7.0.2046.569) and Skype for Business Server Subscription Edition CU1 (7.0.2046.0 through before 7.0.2046.879) are affected.
Is there a patch for CVE-2026-66302?
Yes. Microsoft released fixes in versions 6.0.9319.885, 7.0.2046.569 and 7.0.2046.879 for the affected Skype for Business Server branches.
Does CVE-2026-66302 require authentication?
No. The vulnerability in Skype for Business Server can be exploited without authentication or user interaction; only network access is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-66302
- cve.org/CVERecord?id=CVE-2026-66302
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026