CVE-2026-63269

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions LibreOffice does not follow playlists that name further resources, and linked media is under link update control.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets2 URLs
Full discourse1 post
  • Dark Web Intelligence@DailyDarkWeb

    ⚠️ MALICIOUS SPREADSHEETS CAN RUN CODE IN LIBREOFFICE AND APACHE OPENOFFICE Both open-source office suites have published advisories for document flaws that trigger as soon as a crafted file is opened. LibreOffice (announced Oct 5): * CVE-2026-63277: a Calc spreadsheet's external data link could name a Java database driver hosted remotely, so opening the document could run Java code from that location * Same batch also fixes arbitrary file write (CVE-2026-63266), local file read / SSRF (CVE-2026-63267, CVE-2026-63268, CVE-2026-63269) and environment/INI value leaks (CVE-2026-63270) * Fixed in LibreOffice 26.2.5 and 26.8.0 Apache OpenOffice: * CVE-2026-59265, rated CRITICAL: a crafted document can execute arbitrary, even remote, code through the Java integration * Affects 4.1.16 and older; the fix (4.1.17) is still in the release-candidate phase * Mitigation now: Tools > Options > OpenOffice > Java, untick "Use a Java runtime environment" ⚠️ Analyst Note: Researchers have published proof-of-concept files. No in-the-wild exploitation has been confirmed. Booby-trapped spreadsheets are a classic phishing lure, so update LibreOffice now, disable Java in OpenOffice until 4.1.17 ships, and don't open untrusted documents. Official advisories: https://www.libreoffice.org/about-us/security/advisories/ https://www.openoffice.org/security/cves/CVE-2026-59265.html #LibreOffice #OpenOffice #CVE #Vulnerability #PatchNow #CyberSecurity #DDW

    0031576.4K
    206.8K followersView on X

Explore more