CVE-2026-66305

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*

History

16 Sep 2026, 19:24

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66305 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66305 - Patch, Vendor Advisory
First Time Microsoft
Microsoft skype For Business Server Subscription Edition
Microsoft skype For Business Server
CPE cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*

Information

Published : 2026-09-08 19:18

Updated : 2026-09-16 19:24


NVD link : CVE-2026-66305

Mitre link : CVE-2026-66305

CVE.ORG link : CVE-2026-66305


JSON object : View

Products Affected

microsoft

  • skype_for_business_server
  • skype_for_business_server_subscription_edition
CWE
CWE-603

Use of Client-Side Authentication