CVE-2026-69642

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*

History

16 Sep 2026, 19:26

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69642 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69642 - Patch, Vendor Advisory
CPE cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
First Time Microsoft
Microsoft skype For Business Server Subscription Edition
Microsoft skype For Business Server

Information

Published : 2026-09-08 19:19

Updated : 2026-09-16 19:26


NVD link : CVE-2026-69642

Mitre link : CVE-2026-69642

CVE.ORG link : CVE-2026-69642


JSON object : View

Products Affected

microsoft

  • skype_for_business_server
  • skype_for_business_server_subscription_edition
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')