Researchers disclosed CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice, flaws that let a malicious spreadsheet run code without triggering macro warnings. The attack chains legitimate features: a spreadsheet defines a database range that downloads an ODB database file from a web address, and that file references a JDBC driver, causing automatic download and execution of attacker-controlled Java code. LibreOffice fixed the issue in versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains affected through 4.1.16 with 4.1.17 still in testing. The technique exists only as a proof of concept, credited to researchers at V12 and Codean Labs.