Description
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery in Skype for Business servers that permits an unauthenticated attacker to cause the server to make arbitrary HTTP requests to internal or external resources, leading to disclosure of sensitive information. Because the flaw originates on the server side, the attacker need not have credentials or prior access; this is a typical SSRF scenario identified with CWE‑918. The disclosed data could include internal network details, configuration information, or other content accessible to the server, compromising confidentiality.

Affected Systems

Microsoft has identified the flaw in Skype for Business Server 2015 released with Cumulative Update 13, the 2019 edition released with Cumulative Update 8, and the Subscription Edition released with CU1. All three versions include the affected component and are vulnerable until the Microsoft security update is applied.

Risk and Exploitability

Microsoft lists the vulnerability with a CVSS score of 7.5. The EPSS score is not available, and the issue is not currently in the CISA KEV catalog. Attackers can exploit the SSRF by forging requests to the server; no authentication is required, implying a low barrier to entry from an external or compromised internal host. The risk is therefore moderate to high, especially in environments where the server has broad network reach or where internal resources are exposed to the internet. Prompt remediation is advised.

Generated by OpenCVE AI on September 9, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update released for Skype for Business Server 2015 CU13, 2019 CU8, or Subscription Edition CU1 as appropriate.
  • Restrict outbound traffic from the server to only necessary destinations and place the server behind a firewall that blocks or filters suspicious internal requests.
  • Enable detailed logging of outbound requests and monitor for anomalous SSRF activity, investigating any irregular traffic promptly.

Generated by OpenCVE AI on September 9, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Wed, 09 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Title Skype for Business Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:14.629Z

Reserved: 2026-07-24T18:06:51.294Z

Link: CVE-2026-66304

cve-icon Vulnrichment

Updated: 2026-09-08T19:55:06.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:07.950

Modified: 2026-09-16T19:23:28.337

Link: CVE-2026-66304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:43Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)