CyberRota Analysis
AI-GeneratedSkype for Business is vulnerable to external control of file names or paths, enabling unauthorized attackers to execute arbitrary code remotely. This critical vulnerability poses a significant risk to the integrity and confidentiality of communications within the application. Organizations using Skype for Business should prioritize immediate remediation to mitigate potential exploitation.
CVE
CVE-2026-66302
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%
Original NVD Description
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.