LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can trigger code execution in LibreOffice and Apache OpenOffice when Java support is enabled, without showing the usual macro warning. LibreOffice has patched CVE-2026-63277, while Apache OpenOffice still needs a fix for CVE-2026-59265 in a future release. #LibreOffice #ApacheOpenOffice #CVE-2026-63277 #CVE-2026-59265

Keypoints

  • A malicious spreadsheet can run attacker code when opened.
  • The attack works only if Java support is enabled.
  • LibreOffice fixed the issue in updates released on October 5.
  • Apache OpenOffice remains affected through version 4.1.16.
  • The exploit abuses database ranges, ODB files, and JDBC drivers to reach code execution.

Read More: https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html