CVE-2026-66302 – Skype for Business Remote Code Execution Vulnerability

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A single crafted network request could turn an exposed Skype for Business server into a path for full remote code execution.”

CVE-2026-66302 is a critical remote code execution vulnerability in affected Microsoft Skype for Business Server versions. External control of a file name or path allows an unauthenticated attacker to send a specially crafted network request that writes an attacker-controlled file to an arbitrary location on the server. Successful exploitation could allow code execution on the target server without authentication or user interaction.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-73
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.