CVE-2026-66306
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information o
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-209
Not enough EPSS history yet.
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-696845.5 MED—
———Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.5hCVE-2026-695525.7 MED—
———Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.5hCVE-2026-692945.5 MED—
———Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.5hCVE-2026-688865.5 MED—
———Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.5hCVE-2026-673836.5 MED—
———Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.5hCVE-2026-118736.5 MED25.0%
——8An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.7d