ZeroHour

CVE-2026-69646

mass

Cryptographic signature spoofing flaw in Microsoft Skype for Business

CVSS 3.1
8.3 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-69646 is an improper verification of a cryptographic signature (CWE-347) in Microsoft Skype for Business that allows an unauthorized attacker to perform spoofing over an adjacent network. An attacker positioned on an adjacent network — for example, on the same LAN segment or connected via VPN — can present forged data that the software fails to correctly signature-verify, without needing credentials or user interaction. Because the CVSS vector rates confidentiality and integrity impact as high (base score 8.3), successful spoofing plausibly lets the attacker impersonate legitimate Skype for Business entities in communications sessions. Organizations running affected Skype for Business deployments, typically on-premises or hybrid enterprise environments, are affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, so no confirmed exploitation has been reported yet.

What to do: Monitor Microsoft's security advisory for this CVE and apply the official Skype for Business security update as soon as it is published, confirming the affected versions from Microsoft rather than this data. In the interim, limit adjacent-network exposure by segmenting Skype for Business servers and restricting which hosts and VPN zones can reach them, and inventory on-premises and hybrid deployments to identify where the product is still in use. Given the low EPSS and lack of a public PoC, patch at normal priority, prioritizing internet-adjacent and internal trust-boundary deployments.

Affected
Microsoft Skype for Business
Estimated exposure
mass≈ millions of enterprise users worldwide (historically 55M+ users, now reduced by Teams migrations) — Skype for Business is a widely deployed Microsoft enterprise communications platform that historically served tens of millions of users across tens of thousands of organizations, and on-premises/hybrid installations persist despite ongoing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Weakness
CWE-347
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.