External Control of File Name or Path in Skype for Business Server and Skype for Business Server Subscription Edition - CVE-2026-66302
Published: September 9, 2026
Vulnerability identifier: #VU148358
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66302
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to external control of file name or path in Skype for Business. A remote attacker can execute arbitrary code on the target system.
Affected software
Skype for Business Server
Skype for Business Server Subscription Edition
Skype for Business Server Subscription Edition
How to mitigate CVE-2026-66302
Install updates from vendor's website.
Skype for Business Server - addressed in versions 6.0.9319.885, 7.0.2046.569
Skype for Business Server Subscription Edition - update to 7.0.2046.879
Skype for Business Server Subscription Edition - update to 7.0.2046.879