Skip to content
LibreOffice Vulnerabilities Disclosed in USN-8868

LibreOffice Vulnerabilities Disclosed in USN-8868

First seen 6 Oct 2026, 09:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 11:27 UTC

Multiple vulnerabilities were discovered in LibreOffice that could allow attackers to crash the application or execute arbitrary code. Key issues include improper handling of WMF image imports (CVE-2026-63272), PDF document imports (CVE-2026-63273, CVE-2026-63274), and CFF fonts (CVE-2026-63275, CVE-2026-63276). Additionally, vulnerabilities were found in URL validation (CVE-2026-63278) and PICT image imports (CVE-2026-63279). These vulnerabilities affect various versions of LibreOffice across different Ubuntu distributions. Patches have been released to address these issues, and users are advised to update their systems promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-05
CVE-2026-50593 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-63272 to CVE-2026-63279 published
Multiple vulnerabilities in LibreOffice were disclosed, affecting various document handling features.
Ubuntu
2026-09-22
CVE-2026-63275 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-63278 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-63276 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-63273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-63274 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
Patches released for LibreOffice vulnerabilities
Ubuntu released patches for the identified vulnerabilities in LibreOffice, urging users to update their systems.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-50593 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of LibreOffice are affected?
Versions of LibreOffice across Ubuntu 22.04, 24.04, and 26.04 LTS are affected.
What types of attacks can these vulnerabilities enable?
Attackers could potentially crash LibreOffice or execute arbitrary code through crafted documents.
How urgent is it to apply the patches?
It is critical to apply the patches immediately to mitigate the risk of exploitation.