CVE-2026-4430Patch(libreoffice / libreoffice)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch libreoffice libreoffice systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libreoffice

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-25)
  • 4 total mentions across 3 days

Affected systems

Products
libreoffice

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-07: 1Mentions · 2026-05-15: 1Mentions · 2026-06-25: 2Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-25: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-25: 205-0705-1506-25
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-151
Patch1
2026-06-252
Patch2
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    LibreOffice heap overflow (CVE-2026-4430) patched in Mageia. My script applies the fix. But you need more than patches – you need to understand malware. Read more -> http://tinyurl.com/46frznz9 https://t.co/2dHZTsE6Dw

    Post summary

    The tweet confirms that the LibreOffice heap overflow CVE-2026-4430 has been patched in Mageia, with an accompanying script for the fix, but does not mention active exploitation or a PoC.

    1001066
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:28922: Atualização de segurança do LibreOffice para Rocky Linux 8 corrige CVE-2026-4430 (out-of-bounds write em OOXML) e outras 4 vulnerabilidades. Saiba mais: -> http://tinyurl.com/4t2p5pec #RockyLinux https://t.co/ISEGmOxQOw

    Post summary

    The tweet announces a Rocky Linux 8 security update that patches CVE‑2026‑4430 (an out‑of‑bounds write in OOXML) along with four other vulnerabilities.

    1000090
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:28922: Atualização de segurança do LibreOffice para Rocky Linux 8 corrige CVE-2026-4430 (out-of-bounds write em OOXML) e outras 4 vulnerabilidades. Saiba mais: -> http://tinyurl.com/4t2p5pec #RockyLinux https://t.co/77mkjOnzRm

    Post summary

    The tweet announces a LibreOffice security update for Rocky Linux 8 that fixes CVE-2026-4430, an out‑of‑bounds write in OOXML, with no PoC or active exploitation reported.

    1000081
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4430 Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects Lib… https://www.cve.org/CVERecord?id=CVE-2026-4430

    Post summary

    The post announces CVE-2026-4430, detailing an out‑of‑bounds write in LibreOffice caused by mismatched encryption salts, but offers no proof‑of‑concept, exploitation details, or remediation advice.

    0000092
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibreofficelibreoffice---

Explore more