← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

LibreOffice and OpenOffice Flaws Allow Code Execution via Malicious Spreadsheets

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malicious spreadsheets can execute code in LibreOffice and OpenOffice.
  • Attack requires Java support to be enabled in the office suite.
  • LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0.
  • Apache OpenOffice (CVE-2026-59265) is still vulnerable up to 4.1.16.

Vulnerability Details

Security researchers have identified flaws in LibreOffice and Apache OpenOffice that enable arbitrary code execution through specially crafted spreadsheets. The attack bypasses typical macro security warnings, allowing code to run as soon as the file is opened. This vulnerability is contingent on the office suite having Java support enabled.

Technical Mechanism

The attack exploits the 'database range' feature in Calc spreadsheets, which can pull and refresh data from external sources like ODB files. An ODB file, specified by a web address within the spreadsheet, can then reference a Java database driver (JDBC). The program downloads this driver, which can be a JAR file containing attacker-controlled code, and executes it. While each component functions as designed, their combination allows for code execution without user consent or warning.

LibreOffice Patch Status

LibreOffice has addressed its vulnerability, tracked as CVE-2026-63277, in updates released on October 5. Users are advised to upgrade to version 26.2.5 or 26.8.0 to mitigate the risk, as all prior versions are affected.

Apache OpenOffice Status and Mitigation

Apache OpenOffice has not yet released a fix for its corresponding flaw, CVE-2026-59265. All versions up to and including the current release, 4.1.16, are vulnerable. A patch is anticipated in version 4.1.17, which is currently undergoing testing. Until then, Apache OpenOffice users can disable Java support within the program's settings or avoid opening untrusted spreadsheets to prevent exploitation.

Impact and Scope

The proof of concept demonstrated the execution of the Calculator app, but the method allows for any Java code to be run. The researchers confirmed the attack works on both Windows and Linux operating systems. While no real-world attacks have been reported, the vulnerability poses a risk to users who might open malicious documents from untrusted sources.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 06

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researchers discovered vulnerabilities in LibreOffice and Apache OpenOffice that allow malicious spreadsheets to execute code without macro warnings when Java support is enabled. LibreOffice has patched its flaw (CVE-2026-63277) in recent updates, while Apache OpenOffice (CVE-2026-59265) remains vulnerable, with a fix expected in version 4.1.17. This impacts users of both office suites, particularly those who open untrusted documents with Java enabled.