AI analysis
CVE-2026-66302 is a critical (CVSS 9.8) vulnerability in Microsoft Skype for Business in which an external attacker controls the file name or path used by the software (CWE-73, external control of file name or path). The flaw is exploitable over a network with no authentication, no privileges, and no user interaction, so a remote unauthenticated attacker who can reach the affected Skype for Business service can trigger it. Successful exploitation yields remote code execution on the target, with high impact on confidentiality, integrity, and availability. Any organization running the affected Skype for Business deployment, presumably the on-premises Skype for Business server product, is affected; the available data does not specify the exact affected version ranges. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns roughly a 0.5% probability of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Apply Microsoft's September 2026 Patch Tuesday updates for Skype for Business as soon as testing permits, since the fix is delivered through that release. Until patched, restrict network access to Skype for Business services (for example, firewall or VPN rules limiting who can reach the server), and identify any Skype for Business endpoints exposed to the internet for prioritized patching and monitoring. Check vendor advisory pages for the specific affected and fixed version numbers for your deployment.
Affected
| Microsoft Skype for Business | — |
Estimated exposure
largelikely tens of thousands of on-premises Skype for Business servers across thousands of organizations (estimated; Microsoft publishes no current install counts) — No install-base figures were provided, so this order-of-magnitude estimate is extrapolated from Skype for Business's long-standing enterprise deployment footprint, with actual exposure limited to instances reachable over the network and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.