CVE-2026-69646
- EPSS 0.21%
- Veröffentlicht 08.09.2026 19:19:04
- Zuletzt bearbeitet 16.09.2026 19:26:34
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-69642
- EPSS 0.27%
- Veröffentlicht 08.09.2026 19:19:03
- Zuletzt bearbeitet 16.09.2026 19:26:02
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66305
- EPSS 0.3%
- Veröffentlicht 08.09.2026 19:18:08
- Zuletzt bearbeitet 16.09.2026 19:24:00
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
CVE-2026-66306
- EPSS 0.51%
- Veröffentlicht 08.09.2026 19:18:08
- Zuletzt bearbeitet 16.09.2026 19:24:24
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVE-2026-66307
- EPSS 0.65%
- Veröffentlicht 08.09.2026 19:18:08
- Zuletzt bearbeitet 16.09.2026 19:24:44
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
CVE-2026-66308
- EPSS 0.61%
- Veröffentlicht 08.09.2026 19:18:08
- Zuletzt bearbeitet 16.09.2026 19:25:08
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-63523
- EPSS 0.67%
- Veröffentlicht 08.09.2026 19:18:07
- Zuletzt bearbeitet 16.09.2026 19:21:56
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66302
- EPSS 0.54%
- Veröffentlicht 08.09.2026 19:18:07
- Zuletzt bearbeitet 16.09.2026 19:22:34
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-66303
- EPSS 0.79%
- Veröffentlicht 08.09.2026 19:18:07
- Zuletzt bearbeitet 16.09.2026 19:23:02
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
CVE-2026-66304
- EPSS 0.71%
- Veröffentlicht 08.09.2026 19:18:07
- Zuletzt bearbeitet 16.09.2026 19:23:28
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.