Vulnerability
Published 2026-10-02
Verified 2026-10-06

Apache OpenOffice CVE-2026-59265 (Critical) and LibreOffice CVE-2026-63277: malicious spreadsheet runs remote Java code on open with no macro prompt; LibreOffice fixed in 26.2.5 / 26.8.0, OpenOffice 4.1.17 still in RC; public proof-of-concept

Apache OpenOffice security bulletin CVE-2026-59265 (oss-security announce by Dave Fisher, 2 October 2026) rates Critical a code-execution issue in the Java integration: a crafted untrusted document can run arbitrary code, including code fetched remotely, when the user opens it. Affected: Apache OpenOffice through 4.1.16 (older OpenOffice.org builds may also be affected); the fix is due in 4.1.17, still a release candidate as of 6 October. LibreOffice published the matching flaw as CVE-2026-63277 on 5 October: a Calc cell range linked to an external data source can name a Java database (JDBC) driver to load from a remote location, so opening the document runs that Java code; fixed versions only accept local file URLs in the Java class path. LibreOffice fixed it in 26.2.5 and 26.8.0, alongside five related Codean Labs findings announced the same day (CVE-2026-63266 arbitrary file write via an embedded Firebird database, CVE-2026-63267 and 63268 local file read and SSRF through external data links, CVE-2026-63269 local file read and SSRF through GStreamer HLS playlists on Linux, CVE-2026-63270 environment and ini value leaks). The Hacker News (6 Oct) reports the chain needs Java support enabled, shows no macro-style warning, works on Windows and Linux, and that the V12 security team has published a proof-of-concept for both suites; no use in real attacks has been reported. Credit: Thomas Rinsma and Edoardo Geraci (Codean Labs) and Rick de Jager (V12), independently; Caolán McNamara (Collabora) wrote the LibreOffice fix. No numeric CVSS published by either project; do not invent a score.

Product
Apache OpenOffice and LibreOffice (Calc external data links, Java/JDBC integration)
Versions
Apache OpenOffice: affected through 4.1.16; fix expected in 4.1.17 (release candidate). LibreOffice: affected before 26.2.5 and 26.8.0; fixed in 26.2.5 / 26.8.0.
Exploited in Australia?
unknown
Patch to
LibreOffice: upgrade to 26.2.5 or 26.8.0 now (public proof-of-concept exists). Apache OpenOffice: upgrade to 4.1.17 when released; until then disable Java runtime integration (Tools > Options > OpenOffice > Java, untick Use a Java runtime environment) and do not open untrusted spreadsheets. Consider switching OpenOffice users to a supported, patched suite.

Primary: Apache OpenOffice — CVE-2026-59265 (Critical; 2 Oct 2026) · Vendor: Apache OpenOffice Security Team · CVE: CVE-2026-59265, CVE-2026-63277, CVE-2026-63266, CVE-2026-63267, CVE-2026-63269, CVE-2026-63270 · LibreOffice security advisories — CVE-2026-63277 and related CVE-2026-63266 to 63270 (5 Oct 2026)

vulnerabilities endpoint