← All articles

LibreOffice and OpenOffice flaws let malicious spreadsheets run code without macro warnings

Researchers disclosed CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice, flaws that let a malicious spreadsheet run code without triggering macro warnings. The attack chains legitimate features: a spreadsheet defines a database range that downloads an ODB database file from a web address, and that file references a JDBC driver, causing automatic download and execution of attacker-controlled Java code. LibreOffice fixed the issue in versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains affected through 4.1.16 with 4.1.17 still in testing. The technique exists only as a proof of concept, credited to researchers at V12 and Codean Labs.

Check
Upgrade LibreOffice to 26.2.5 or 26.8.0, and for Apache OpenOffice avoid opening untrusted spreadsheets until 4.1.17 ships, disabling automatic database and JDBC features.
Affected
Vulnerable LibreOffice and OpenOffice versions let a crafted spreadsheet download a database file and JDBC driver that runs attacker Java code without any macro warning.
Fix
Apply the LibreOffice fixes, restrict or disable JDBC and external database connections, and treat spreadsheets from untrusted sources as potentially executable content.