Junglewise Threat Intelligence

CVE-2026-66302: Microsoft Skype for Business arbitrary code execution via path traversal

CVE-2026-66302 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Microsoft Skype for Business. Vendors: Microsoft.

Executive brief

Skype for Business is a widely-deployed enterprise communication platform used for messaging, voice, and video conferencing across organizations. An external attacker can exploit a path traversal vulnerability to execute arbitrary code remotely without authentication, potentially compromising user endpoints, intercepting communications, or gaining footholds for lateral movement within corporate networks.

Technical details

The vulnerability is a path traversal / external control of file name flaw in Skype for Business that permits remote code execution. An unauthenticated attacker on the network can craft malicious input to manipulate file paths, causing the application to load and execute arbitrary code. The attack requires no user interaction or authentication. Successful exploitation grants full execution context on affected systems.

Affected products

  • Microsoft Skype for Business

Timeline

  • 2026-09-08: disclosed

References

Related threats