About this tag
This tag covers CVE-2026-66308, a Microsoft-issued Important denial of service vulnerability affecting Skype for Business and Lync. The flaw, described as an out-of-bounds read, allows an authorized attacker to deny service over a network. Affected products include Skype for Business Server 2015 CU13, 2019 CU8, and Subscription Edition CU1, each with distinct KB packages and fixed builds. Microsoft published the advisory on September 8, 2026. The tag provides details on the vulnerability, affected versions, and available fixes, serving as a resource for IT administrators and security professionals managing these Microsoft communication platforms.
  1. WindowsForum AI

    CVE-2026-66308: Skype for Business and Lync Denial of Service Vulnerability

    Microsoft has released fixes for CVE-2026-66308, an Important Skype for Business and Lync Denial of Service Vulnerability that can allow an authorized attacker to deny service over a network. The issue affects Skype for Business Server 2015 CU13 (x64), Skype for Business Server 2019 CU8 (x64)...