LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
LibreOffice patched spreadsheet code execution; matching OpenOffice flaw CVE-2026-59265 remains unfixed.
Researchers showed that opening a Calc spreadsheet can refresh a database range, download an ODB file, and load an attacker-controlled JDBC driver, running Java code without a macro warning when Java support is enabled. LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0 on October 5. Apache OpenOffice CVE-2026-59265 is unpatched through 4.1.16, with a fix expected in 4.1.17. V12 published proof-of-concept files, and there are no reports of in-the-wild use.
66