Thehackernews RCE Vulnerability in LibreOffice and OpenOffice Spreadsheets
Article Content
- •CVE-2026-63277 in LibreOffice is a high-risk RCE vulnerability fixed in recent updates.
- •Apache OpenOffice remains vulnerable with an unpatched CVE-2026-59265, affecting all versions up to 4.1.16.
- •Users should disable Java support or avoid untrusted spreadsheets until OpenOffice releases a fix.
A remote code execution vulnerability has been identified in LibreOffice and Apache OpenOffice, allowing malicious spreadsheets to execute attacker-controlled code without user consent. The flaw, tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for OpenOffice, exploits a feature that enables spreadsheets to link to external data sources. LibreOffice has released patches in versions 26.2.5 and 26.8.0 on October 5, 2026, while OpenOffice has not yet patched the vulnerability in its current version, 4.1.16. Users are advised to disable Java support or avoid untrusted spreadsheets until a fix is available. The vulnerability has been demonstrated in proof-of-concept scenarios, but there are no confirmed reports of exploitation in the wild. The issue affects systems where Java and JDBC support are enabled, particularly on Linux desktops. The risk level for LibreOffice's CVE-2026-63277 is rated as high with a CVSS score of 8.5.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Apache OpenOffice and CVE-2026-59265 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of LibreOffice are patched?
What should OpenOffice users do?
Is there confirmed exploitation of these vulnerabilities?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…