SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-66302

CRITICAL · CVSS 9.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Skype for Business is vulnerable to external control of file names or paths, enabling unauthorized attackers to execute arbitrary code remotely. This critical vulnerability poses a significant risk to the integrity and confidentiality of communications within the application. Organizations using Skype for Business should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-66302
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%

Original NVD Description

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.