Skip to content
MicrosoftCVE-2026-69646

Microsoft Skype for Business: spoofing

High8.3CVE-2026-69646 · Published Sep 8, 2026 · updated Sep 16, 2026

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Skype for Business Server 2015 CU13
Product
>= 9319.0, < 6.0.9319.8856.0.9319.885
Skype for Business Server 2019 CU8
Product
>= 2046.0, < 7.0.2046.5697.0.2046.569
Skype for Business Server Subscription Edition CU1
Product
>= 2046.0, < 7.0.2046.8797.0.2046.879
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-347

More Microsoft advisories

All Microsoft
Advisory
Microsoft Skype for Business: cross-site scripting
Medium6.5Sep 8
Microsoft Skype for Business: spoofing
High7.1Sep 8
Microsoft Skype for Business: information disclosure
Medium6.5Sep 8
Microsoft Skype for Business: integer overflow
High7.5Sep 8
Microsoft Skype for Business: out-of-bounds read
Medium6.5Sep 8
Microsoft Skype for Business: cross-site scripting
Medium6.5Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.