Description
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
Published: 2026-09-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing via forged cryptographic signatures
Action: Immediate Patch
AI Analysis

Impact

Improper verification of cryptographic signatures in Microsoft Skype for Business Server allows an unauthorized attacker to impersonate legitimate users or devices over an adjacent network. The flaw enables the attacker to send traffic that the server will accept as authenticated, potentially leading to unauthorized access to resources or data. The impact is primarily the ability to spoof identity within the Skype for Business environment, which could be leveraged for further attacks such as eavesdropping or credential theft.

Affected Systems

The vulnerability affects Microsoft Skype for Business Server 2015 CU13, Microsoft Skype for Business Server 2019 CU8, and Microsoft Skype for Business Server Subscription Edition CU1. No additional version details are provided beyond the specified cumulative update levels.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is also not listed in the CISA KEV catalog. The likely attack vector is an attacker present on a network adjacent to the affected server who can send forged authentication traffic that bypasses proper signature verification. Without a patch, the server is susceptible to identity spoofing and related compromise risks.

Generated by OpenCVE AI on September 9, 2026 at 13:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses the cryptographic signature verification flaw for Skype for Business Server (the update associated with CVE-2026-69646).
  • If a patch cannot be applied immediately, isolate the affected servers from adjacent networks or untrusted segments by implementing network segmentation and firewall rules that block spoofed traffic and restrict direct peer-to-peer connections.
  • Configure and monitor authentication logs for anomalous or repeated authentication attempts, and set up alerts for potential spoofing or impersonation activities.

Generated by OpenCVE AI on September 9, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
Title Skype for Business Spoofing Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-347
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:54.375Z

Reserved: 2026-08-03T21:24:59.409Z

Link: CVE-2026-69646

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:59.541Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:19:04.560

Modified: 2026-09-16T19:26:34.540

Link: CVE-2026-69646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:15:01Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature