Vulnerability Details CVE-2026-66302
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 44.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-66302
-
cpe:2.3:a:microsoft:skype_for_business_server:2015
-
cpe:2.3:a:microsoft:skype_for_business_server:2019