Vulnerability Intelligence Report
Skype for Business Spoofing Vulnerability
CVE-2026-69646
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
No Active Exploit Signals
CVSS Base Score
8.3
HIGH
Exploitability:2.9
Impact Score:5.5
EPSS Probability:0.21%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-347 ↗CWE-347: Improper Verification of Cryptographic Signature
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Microsoft | Skype for Business Server 2015 CU13 | 9319.0 < 6.0.9319.885 (affected) |
| Microsoft | Skype for Business Server 2019 CU8 | 2046.0 < 7.0.2046.569 (affected) |
| Microsoft | Skype for Business Server Subscription Edition CU1 | 2046.0 < 7.0.2046.879 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.206%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Microsoft Corporation · Vendor · USA |
| Reserved | 2026-08-03T21:24:59 |
| Published | 2026-09-08T18:33:11 |
| Patch Date | 2026-09-08 |
| Last Updated | 2026-09-23T22:34:12 |
Community Chatter & Buzz