← Vulnerability feed

Vulnerability record · CVE-2026-66304 · published 8 September 2026

CVE-2026-66304: Microsoft skype for business server server-side request forgery (ssrf) vulnerability

Microsoft · Skype For Business Server

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

7.5 CVSS 3.1 High EPSS 0.97% · top 39.5% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
16 Sep 2026Last modified by NVD

Description

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-66304 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2023-41763Microsoft Skype for Business Server SSRF Elevation of PrivilegeCVE-2023-41763 is a server-side request forgery (CWE-918) flaw in Microsoft Skype for Business Server, rated by Microsoft as an elevation of privileg…KEVEPSS 90%analysed9.8CVE-2026-66302Microsoft skype for business server vulnerabilityExternal control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.EPSS 0.97%8.3CVE-2026-69646Microsoft skype for business server improper verification of cryptographic signature vulnerabilityImproper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.EPSS 0.32%7.5CVE-2026-66307Microsoft skype for business server vulnerabilityInteger underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.EPSS 1.2%7.2CVE-2023-36780Microsoft skype for business server untrusted search path vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.6%7.2CVE-2023-36786Microsoft skype for business server vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.5%7.2CVE-2023-36789Microsoft skype for business server code injection vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.4%7.2CVE-2021-26422Microsoft lync server vulnerabilitySkype for Business and Lync Remote Code Execution VulnerabilityEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2026-66304), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.