Security researchers have identified flaws in LibreOffice and Apache OpenOffice that enable arbitrary code execution through specially crafted spreadsheets. The attack bypasses typical macro security warnings, allowing code to run as soon as the file is opened. This vulnerability is contingent on the office suite having Java support enabled.
The attack exploits the 'database range' feature in Calc spreadsheets, which can pull and refresh data from external sources like ODB files. An ODB file, specified by a web address within the spreadsheet, can then reference a Java database driver (JDBC). The program downloads this driver, which can be a JAR file containing attacker-controlled code, and executes it. While each component functions as designed, their combination allows for code execution without user consent or warning.
LibreOffice has addressed its vulnerability, tracked as CVE-2026-63277, in updates released on October 5. Users are advised to upgrade to version 26.2.5 or 26.8.0 to mitigate the risk, as all prior versions are affected.
Apache OpenOffice has not yet released a fix for its corresponding flaw, CVE-2026-59265. All versions up to and including the current release, 4.1.16, are vulnerable. A patch is anticipated in version 4.1.17, which is currently undergoing testing. Until then, Apache OpenOffice users can disable Java support within the program's settings or avoid opening untrusted spreadsheets to prevent exploitation.
The proof of concept demonstrated the execution of the Calculator app, but the method allows for any Java code to be run. The researchers confirmed the attack works on both Windows and Linux operating systems. While no real-world attacks have been reported, the vulnerability poses a risk to users who might open malicious documents from untrusted sources.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers discovered vulnerabilities in LibreOffice and Apache OpenOffice that allow malicious spreadsheets to execute code without macro warnings when Java support is enabled. LibreOffice has patched its flaw (CVE-2026-63277) in recent updates, while Apache OpenOffice (CVE-2026-59265) remains vulnerable, with a fix expected in version 4.1.17. This impacts users of both office suites, particularly those who open untrusted documents with Java enabled.