CVE-2026-63523HighCVSS 6.5
Skype for Business Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
🎯 Affected products3
- Skype for Business Server 2015 CU13
- Skype for Business Server 2019 CU8
- Skype for Business Server Subscription Edition CU1
✅ Remediation
KB5123301 (Security Update) — fixed build 6.0.9319.885 KB5123287 (Security Update) — fixed build 7.0.2046.879 KB5123300 (Security Update) — fixed build 7.0.2046.569