LibreOffice patches spreadsheet code bug; OpenOffice flaw unfixed
LibreOffice fixed a no-warning spreadsheet code-execution flaw; related OpenOffice CVE-2026-59265 remains unpatched through 4.1.16.
Researchers showed that opening a Calc spreadsheet can refresh a database range, download an ODB file, and load an attacker-controlled JDBC driver, executing Java code without a macro warning when Java support is enabled. LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0 on October 5. Apache OpenOffice CVE-2026-59265 remains unpatched through 4.1.16, with a fix expected in 4.1.17. V12 published proof-of-concept files, and no in-the-wild attacks are reported. An October 8 oss-security reply asks whether CVE-2026-59265, described there as system takeover by opening a malicious OpenOffice document, also applies to LibreOffice, but it supplies no technical details; the reports therefore do not establish that the OpenOffice CVE itself covers LibreOffice, which is assigned the separate, already patched CVE-2026-63277.
- Opening a Calc spreadsheet can refresh a database range, download an ODB file, and load an attacker-controlled JDBC driver, running Java code without a macro warning when Java support is enabled.
- LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0 on October 5.
- Apache OpenOffice CVE-2026-59265 is unpatched through 4.1.16, with a fix expected in 4.1.17.
- V12 published proof-of-concept files; there are no reports of in-the-wild use.
- On October 8, Demi Marie Obenour asked on oss-security whether CVE-2026-59265 also affects LibreOffice; the reply adds no versions, patch status, proof, or exploitation evidence.
Coverage timelineoldest first · each row is one article
- · 4d agoLibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
The Hacker News· 66
LibreOffice patched spreadsheet code execution; matching OpenOffice flaw CVE-2026-59265 remains unfixed.
- · 3d agoRe: CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
oss-security· 34
A mailing-list reply asks if OpenOffice takeover bug CVE-2026-59265 also affects LibreOffice.
Vulnerabilities in this storyAll →
- CVE-2026-592658.8<1%Code execution via Java integration in Apache OpenOfficepublished · Apache Software Foundation Apache OpenOffice PoC