
⚠️ MALICIOUS SPREADSHEETS CAN RUN CODE IN LIBREOFFICE AND APACHE OPENOFFICE Both open-source office suites have published advisories for document flaws that trigger as soon as a crafted file is opened. LibreOffice (announced Oct 5): * CVE-2026-63277: a Calc spreadsheet's external data link could name a Java database driver hosted remotely, so opening the document could run Java code from that location * Same batch also fixes arbitrary file write (CVE-2026-63266), local file read / SSRF (CVE-2026-63267, CVE-2026-63268, CVE-2026-63269) and environment/INI value leaks (CVE-2026-63270) * Fixed in LibreOffice 26.2.5 and 26.8.0 Apache OpenOffice: * CVE-2026-59265, rated CRITICAL: a crafted document can execute arbitrary, even remote, code through the Java integration * Affects 4.1.16 and older; the fix (4.1.17) is still in the release-candidate phase * Mitigation now: Tools > Options > OpenOffice > Java, untick "Use a Java runtime environment" ⚠️ Analyst Note: Researchers have published proof-of-concept files. No in-the-wild exploitation has been confirmed. Booby-trapped spreadsheets are a classic phishing lure, so update LibreOffice now, disable Java in OpenOffice until 4.1.17 ships, and don't open untrusted documents. Official advisories: https://www.libreoffice.org/about-us/security/advisories/ https://www.openoffice.org/security/cves/CVE-2026-59265.html #LibreOffice #OpenOffice #CVE #Vulnerability #PatchNow #CyberSecurity #DDW
