CVE-2026-66306

Summary

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftSkype for Business Server 2015 CU139319.0 < 6.0.9319.885affected
MicrosoftSkype for Business Server 2019 CU82046.0 < 7.0.2046.569affected
MicrosoftSkype for Business Server Subscription Edition CU12046.0 < 7.0.2046.879affected

Weaknesses

  • CWE-209: CWE-209: Generation of Error Message Containing Sensitive Information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References