Information Exposure Through an Error Message in Skype for Business Server and Skype for Business Server Subscription Edition - CVE-2026-66306
Published: September 9, 2026
Vulnerability identifier: #VU148395
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66306
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to generation of error message containing sensitive information in Skype for Business. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Skype for Business Server
Skype for Business Server Subscription Edition
Skype for Business Server Subscription Edition
How to mitigate CVE-2026-66306
Install updates from vendor's website.
Skype for Business Server - addressed in versions 6.0.9319.885, 7.0.2046.569
Skype for Business Server Subscription Edition - update to 7.0.2046.879
Skype for Business Server Subscription Edition - update to 7.0.2046.879