Description
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing via cross‑site scripting
Action: Patch
AI Analysis

Impact

An attacker who is not authorized can inject malicious scripts into web pages generated by Skype for Business Server. The cross‑site scripting flaw allows the injected code to run in the context of the victim's session, enabling the attacker to make the system appear to be communicating with a different user or service, thereby spoofing identities over the network.

Affected Systems

The vulnerability affects Microsoft Skype for Business Server 2015 on CU13, Skype for Business Server 2019 on CU8, and Skype for Business Server Subscription Edition on CU1. All three product lines suffer from the same cross‑site scripting flaw that can be exploited by any user who can load a manipulated web page.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the threat is not widely exploited yet. The likely attack vector is a web‑based one, with an attacker sending malicious content to a user who then interacts with a compromised web page. The impact is the ability to impersonate another user or service within Skype for Business, potentially leading to misinformation or deception of other participants.

Generated by OpenCVE AI on September 9, 2026 at 13:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update listed in the internal Microsoft Security Response Center for CVE-2026-63523 to fully patch all affected Skype for Business Server installations.
  • If a patch cannot be applied immediately, configure the services so that only sanitized web pages are served to clients, removing or blocking any external or untrusted scripts that could be injected.
  • Enforce TLS for all client‑server traffic and enable browser settings that block or warn about active scripting on untrusted origins.

Generated by OpenCVE AI on September 9, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Title Skype for Business Spoofing Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:13.594Z

Reserved: 2026-07-16T22:05:22.740Z

Link: CVE-2026-63523

cve-icon Vulnrichment

Updated: 2026-09-11T20:56:54.185Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:07.267

Modified: 2026-09-16T19:21:56.487

Link: CVE-2026-63523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T23:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')