CVE-2026-63267

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets2 URLs
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    ⚠️ MALICIOUS SPREADSHEETS CAN RUN CODE IN LIBREOFFICE AND APACHE OPENOFFICE Both open-source office suites have published advisories for document flaws that trigger as soon as a crafted file is opened. LibreOffice (announced Oct 5): * CVE-2026-63277: a Calc spreadsheet's external data link could name a Java database driver hosted remotely, so opening the document could run Java code from that location * Same batch also fixes arbitrary file write (CVE-2026-63266), local file read / SSRF (CVE-2026-63267, CVE-2026-63268, CVE-2026-63269) and environment/INI value leaks (CVE-2026-63270) * Fixed in LibreOffice 26.2.5 and 26.8.0 Apache OpenOffice: * CVE-2026-59265, rated CRITICAL: a crafted document can execute arbitrary, even remote, code through the Java integration * Affects 4.1.16 and older; the fix (4.1.17) is still in the release-candidate phase * Mitigation now: Tools > Options > OpenOffice > Java, untick "Use a Java runtime environment" ⚠️ Analyst Note: Researchers have published proof-of-concept files. No in-the-wild exploitation has been confirmed. Booby-trapped spreadsheets are a classic phishing lure, so update LibreOffice now, disable Java in OpenOffice until 4.1.17 ships, and don't open untrusted documents. Official advisories: https://www.libreoffice.org/about-us/security/advisories/ https://www.openoffice.org/security/cves/CVE-2026-59265.html #LibreOffice #OpenOffice #CVE #Vulnerability #PatchNow #CyberSecurity #DDW

    0031576.4K
    206.8K followersView on X

Explore more