Skip to content
RCE Vulnerability in LibreOffice and OpenOffice Spreadsheets

RCE Vulnerability in LibreOffice and OpenOffice Spreadsheets

First seen 6 Oct 2026, 12:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 12:58 UTC
  • •CVE-2026-63277 in LibreOffice is a high-risk RCE vulnerability fixed in recent updates.
  • •Apache OpenOffice remains vulnerable with an unpatched CVE-2026-59265, affecting all versions up to 4.1.16.
  • •Users should disable Java support or avoid untrusted spreadsheets until OpenOffice releases a fix.

A remote code execution vulnerability has been identified in LibreOffice and Apache OpenOffice, allowing malicious spreadsheets to execute attacker-controlled code without user consent. The flaw, tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for OpenOffice, exploits a feature that enables spreadsheets to link to external data sources. LibreOffice has released patches in versions 26.2.5 and 26.8.0 on October 5, 2026, while OpenOffice has not yet patched the vulnerability in its current version, 4.1.16. Users are advised to disable Java support or avoid untrusted spreadsheets until a fix is available. The vulnerability has been demonstrated in proof-of-concept scenarios, but there are no confirmed reports of exploitation in the wild. The issue affects systems where Java and JDBC support are enabled, particularly on Linux desktops. The risk level for LibreOffice's CVE-2026-63277 is rated as high with a CVSS score of 8.5.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-02
CVE-2026-59265 disclosed
Apache OpenOffice's vulnerability allowing RCE was published, affecting versions 4.1.16 and earlier.
Cyberkendra
2026-10-05
LibreOffice patches released
LibreOffice versions 26.2.5 and 26.8.0 were released to fix CVE-2026-63277.
Cyberkendra
2026-10-05
CVE-2026-63269 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-63277 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-63267 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-63268 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-63270 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-63266 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
OpenOffice vulnerability acknowledged
Apache OpenOffice confirmed the vulnerability and advised users to disable Java until a fix is available.
Thehackernews

More articles in this cluster (11)

Following this threat?

Track Apache OpenOffice and CVE-2026-59265 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of LibreOffice are patched?
LibreOffice versions 26.2.5 and 26.8.0 have been patched to fix CVE-2026-63277.
What should OpenOffice users do?
OpenOffice users should disable Java support or avoid opening untrusted spreadsheets until version 4.1.17 is released.
Is there confirmed exploitation of these vulnerabilities?
No confirmed exploitation has been reported in the wild for either CVE at this time.