Microsoft Security Response Center Follow CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302 msrc.microsoft.com