Improper Verification of Cryptographic Signature in Skype for Business Server and Skype for Business Server Subscription Edition - CVE-2026-69646
Published: September 9, 2026
Vulnerability identifier: #VU148423
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69646
CWE-ID: CWE-347
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper verification of cryptographic signature in Skype for Business. A remote attacker on the local network can perform spoofing attack.
Affected software
Skype for Business Server
Skype for Business Server Subscription Edition
Skype for Business Server Subscription Edition
How to mitigate CVE-2026-69646
Install updates from vendor's website.
Skype for Business Server - addressed in versions 6.0.9319.885, 7.0.2046.569
Skype for Business Server Subscription Edition - update to 7.0.2046.879
Skype for Business Server Subscription Edition - update to 7.0.2046.879