CVE-2026-66304
largeUnauthenticated SSRF in Microsoft Skype for Business
CVE-2026-66304 is a server-side request forgery (SSRF) flaw in Microsoft Skype for Business, rated 7.5 High with a network attack vector that requires no privileges and no user interaction. An unauthenticated remote attacker can send crafted requests that cause the Skype for Business service to issue requests on the attacker's behalf, reaching attacker-controlled or otherwise non-public endpoints. Successful exploitation produces a high-impact disclosure of information, with no integrity or availability impact per the CVSS scoring. Organizations running an affected Skype for Business deployment — typically on-premises Skype for Business Server — are in scope, although the available data does not specify affected versions or ranges. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at roughly 0.7%.
What to do: Check Microsoft's advisory for the affected Skype for Business version ranges and apply the patched release when it is published, prioritizing servers whose web or conferencing endpoints are reachable from untrusted networks. Until patching, restrict unauthenticated network access to Skype for Business services (reverse proxies, firewalls, VPN-only access) and review what internal services the server can reach, since SSRF can be used to probe them. No public PoC exists, so this warrants scheduled remediation rather than emergency response.
| Microsoft Skype for Business | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.