ZeroHour

CVE-2026-66304

large

Unauthenticated SSRF in Microsoft Skype for Business

CVSS 3.1
7.5 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-66304 is a server-side request forgery (SSRF) flaw in Microsoft Skype for Business, rated 7.5 High with a network attack vector that requires no privileges and no user interaction. An unauthenticated remote attacker can send crafted requests that cause the Skype for Business service to issue requests on the attacker's behalf, reaching attacker-controlled or otherwise non-public endpoints. Successful exploitation produces a high-impact disclosure of information, with no integrity or availability impact per the CVSS scoring. Organizations running an affected Skype for Business deployment — typically on-premises Skype for Business Server — are in scope, although the available data does not specify affected versions or ranges. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at roughly 0.7%.

What to do: Check Microsoft's advisory for the affected Skype for Business version ranges and apply the patched release when it is published, prioritizing servers whose web or conferencing endpoints are reachable from untrusted networks. Until patching, restrict unauthenticated network access to Skype for Business services (reverse proxies, firewalls, VPN-only access) and review what internal services the server can reach, since SSRF can be used to probe them. No public PoC exists, so this warrants scheduled remediation rather than emergency response.

Affected
Microsoft Skype for Business
Estimated exposure
largelikely on the order of hundreds of thousands of enterprise users, with internet-exposed instances far fewer (estimate) — No install-base or public-scan counts are in the provided data, so this is estimated from Skype for Business's legacy footprint in enterprise on-premises unified communications, where most deployments sit on internal networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.