Threat Intelligence

Booby-Trapped Spreadsheets Can Run Attacker Code in LibreOffice and OpenOffice Without a Macro Warning

The Hacker News · 6 Oct 2026
Key Takeaway Update LibreOffice to a fixed version now, and if your business uses Apache OpenOffice, turn off Java in its settings and avoid untrusted spreadsheets until a patch arrives.

Security researchers have shown that a malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened. Unlike with macros, neither program shows a warning first. The attack only works when Java support is enabled. So far it has been demonstrated only as a proof of concept, and there are no reports of it being used in real attacks.

The attack chains together features that each work as designed. A Calc spreadsheet can hold a "database range" that refreshes itself from an outside source, which can be a database file (ODB) fetched from a web address written into the spreadsheet. That file can name a Java database driver and point to a bundle of Java code on a remote server. The program downloads the code and starts it inside itself. The researchers say this reaches code execution without ever asking the user to trust the document. In their demonstration, the code simply opened the Calculator app, but the same route could run any Java code. They tested it on Windows and Linux.

LibreOffice fixed its flaw (CVE-2026-63277) in updates released on October 5, and recommends version 26.2.5 or 26.8.0. Earlier versions are affected. Apache OpenOffice has not yet fixed its matching flaw (CVE-2026-59265). Every version up to and including 4.1.16 is affected, with a fix expected in version 4.1.17, which is still being tested. Until then, OpenOffice users can turn off Java in the settings or avoid opening spreadsheets they do not trust.

LibreOffice Apache OpenOffice CVE-2026-63277 CVE-2026-59265 Patch Management

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.