Description
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing
Action: Patch
AI Analysis

Impact

The vulnerability originates from improper neutralization of user supplied input during the generation of web pages in Skype for Business. This cross‑site scripting flaw permits an attacker to inject malicious content that causes end‑users to believe they are interacting with a legitimate participant, leading to spoofing over the network.

Affected Systems

The flaw affects Microsoft Skype for Business Server 2015 Community Update 13, Microsoft Skype for Business Server 2019 Update 8, and Microsoft Skype for Business Server Subscription Edition Update 1. Only the specified cumulative update levels are known to be vulnerable.

Risk and Exploitability

The CVSS base score of 6.5 indicates a medium severity that could be leveraged by an attacker who can supply input that is rendered in a web context. No exploitable code or remote code execution is required; spoofing attacks rely on user interaction with a crafted web page. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been confirmed as a known exploited vulnerability. Nevertheless, the potential for social engineering and the impact on user trust warrants timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 13:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Security update for CVE-2026-69642 to all affected Skype for Business Server installations.
  • Restart any servers that received the update to ensure the changes take effect.
  • Regularly review server logs for unusual web page rendering errors and reinforce user training to recognize spoofed content.

Generated by OpenCVE AI on September 9, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Title Skype for Business Spoofing Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:53.787Z

Reserved: 2026-08-03T21:24:59.408Z

Link: CVE-2026-69642

cve-icon Vulnrichment

Updated: 2026-09-09T16:17:46.987Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:19:03.510

Modified: 2026-09-16T19:26:02.013

Link: CVE-2026-69642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:15:01Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')