on September 8, 2026 at 2:00 pm — CVE-2026-66304 Skype for Business Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
Protecting Privacy Build Trust
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.