Microsoft published the advisory on September 8, 2026. The Microsoft Security Response Center describes the flaw as: “Skype for Business Denial of Service Vulnerability: Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.”
The practical consequence is service availability, rather than disclosure or alteration of communications data. The required attacker condition is still important for administrators assessing urgency: the vulnerability is reachable over a network, but it requires authorization. Organizations running an exposed or broadly accessible Skype for Business deployment should treat the server updates as operational maintenance with a security deadline, particularly where conferencing and voice services have limited redundancy.
Microsoft’s severity and exploitation assessment
CVE-2026-66308 is rated Important with a CVSS base score of 6.5 and a temporal score of 5.7. Microsoft identifies the underlying weakness as CWE-125, an out-of-bounds read.
The complete CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C. It describes a network-accessible issue with low attack complexity, low privileges required, and no user interaction required. The scored impact is confined to availability: confidentiality and integrity are scored as having no impact, while availability is scored High.
Microsoft’s public advisory status and exploitation fields are:
- Publicly disclosed: No.
- Exploited: No.
- Customer action required: Yes.
Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should inform prioritization, but it does not remove the need to patch servers that remain in production: the vulnerability can interrupt a service that may support meetings, messaging, telephony, and federated communications for an organization.
The affected Skype for Business Server releases
Microsoft’s affected-product record supplies a separate remediation package for each supported release line. Administrators should match the installed product release to its corresponding KB rather than treating the three builds as interchangeable.
| Affected product | Required update | Fixed build |
|---|---|---|
| Skype for Business Server 2015 CU13 (x64) | KB5123301 | 6.0.9319.885 |
| Skype for Business Server 2019 CU8 (x64) | KB5123300 | 7.0.2046.569 |
| Skype for Business Server Subscription Edition CU1 (x64) | KB5123287 | 7.0.2046.879 |
For Skype for Business Server 2015 CU13 (x64), install KB5123301 to reach fixed build 6.0.9319.885.
For Skype for Business Server 2019 CU8 (x64), install KB5123300 to reach fixed build 7.0.2046.569.
For Skype for Business Server Subscription Edition CU1 (x64), install KB5123287 to reach fixed build 7.0.2046.879.
The fixed-build requirement is the useful verification point after deployment. A change-management record that says an update was approved or downloaded does not establish that the vulnerable server component has reached the remediated version. Teams should confirm the installed Skype for Business Server build against the build numbers Microsoft specifies for their own release branch.
What the denial-of-service scope means for administrators
The advisory’s description is narrowly framed: an out-of-bounds read in Skype for Business permits an authorized attacker to deny service over a network. Microsoft does not describe a data-theft, credential-theft, code-execution, or integrity-impact outcome in the supplied advisory facts. The availability impact, however, can be substantial in a communications platform if the affected server role supports a large number of users or a business-critical service.
Because the CVSS vector requires privileges but no user interaction, organizations should focus their review on who can authenticate to and interact with Skype for Business services, including accounts that may have more access than their intended job role requires. Patch deployment should be paired with the normal review of authorized user access and any exposed service paths, while avoiding the mistake of treating authorization as a substitute for remediation.
The title includes both Skype for Business and Lync, while Microsoft’s affected-product entries in this advisory identify the three Skype for Business Server releases above. For patch planning, the KB-to-build mapping is the authoritative operational detail supplied by Microsoft: KB5123301 for Skype for Business Server 2015 CU13 (x64), KB5123300 for Skype for Business Server 2019 CU8 (x64), and KB5123287 for Skype for Business Server Subscription Edition CU1 (x64).
Patch verification should use the fixed build
CVE-2026-66308 is a case where the product name alone is insufficient for a deployment decision. The three affected entries have different update packages and different target builds, so an administrator maintaining more than one Skype for Business environment must verify each branch independently.
After installing the applicable KB, confirm that the affected server is at 6.0.9319.885 for Skype for Business Server 2015 CU13 (x64), 7.0.2046.569 for Skype for Business Server 2019 CU8 (x64), or 7.0.2046.879 for Skype for Business Server Subscription Edition CU1 (x64). Reaching those builds is Microsoft’s stated remediation for the network denial-of-service flaw.