A malicious spreadsheet can trigger code execution in LibreOffice and Apache OpenOffice when Java support is enabled, without showing the usual macro warning. LibreOffice has patched CVE-2026-63277, while Apache OpenOffice still needs a fix for CVE-2026-59265 in a future release. #LibreOffice #ApacheOpenOffice #CVE-2026-63277 #CVE-2026-59265
Keypoints
- A malicious spreadsheet can run attacker code when opened.
- The attack works only if Java support is enabled.
- LibreOffice fixed the issue in updates released on October 5.
- Apache OpenOffice remains affected through version 4.1.16.
- The exploit abuses database ranges, ODB files, and JDBC drivers to reach code execution.
Read More: https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html