---
title: "LibreOffice Fixes Silent RCE Vulnerability, OpenOffice Still Exposed"
date: 2026-10-06
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/10/libreoffice-java-malicious-spreadsheets-flaw-patch.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# LibreOffice Fixes Silent RCE Vulnerability, OpenOffice Still Exposed

On October 5, LibreOffice applied fixes for a Java-requiring bug which allows for a booby-trapped spreadsheet to execute attacker code when opened for the first time. The flaw bypasses both the LibreOffice and Apache OpenOffice macro warning. No fix is available for OpenOffice.

## What Happened?

- LibreOffice versions before 26.2.5 and 26.8.0 carry the flaw, which the project tracks as CVE-2026-63277.
- Apache OpenOffice is exposed in every release up to and including 4.1.16, under the matching ID CVE-2026-59265.
- The attack works only when the program’s Java support is switched on, and no real-world use has been reported so far.
- V12 and Codean Labs found the LibreOffice bug separately, and V12 has published proof-of-concept files for both programs.

## Four ordinary features add up to code execution

The chain starts with a Calc “**database range**,” a block of cells that pulls data from an outside source and refreshes itself. That source can be an ODB, a separate database file, sitting at a web address written into the spreadsheet. Here is what happens when someone opens the file:

- **The range refreshes, and LibreOffice or OpenOffice downloads the ODB from the attacker’s address.**
- **The ODB names a JDBC (Java Database Connectivity) driver and points to its code, which can be a JAR file on a remote server.**
- **The program fetches the JAR.**
- **It starts the driver, which is the attacker’s code, inside the office suite itself.**

Each piece works as designed, and the researchers say the danger sits in the combination. Together, the steps reach code execution without ever asking the user to trust the document. Both suites ask exactly that question before a macro runs.

In V12’s [proof of concept](https://github.com/v12-security/pocs/tree/main/office_jdbc_bugs), the rogue driver just opens the Calculator app. That’s a harmless stand-in for any Java code an attacker would rather run. The team tested it on Windows and Linux and says the technique isn’t tied to one operating system.

> Someone can email you a LibreOffice spreadsheet that runs their code on your computer the moment you open it. Fixed today in 26.2.5 (CVE-2026-63277), plus five bugs that let a file read or write files on your machine. Update before the next attachment. https://t.co/eOBkHVULvV https://t.co/pKkv7b8s4P
> 
> — HOL (@HashgraphOnline) [October 5, 2026](https://x.com/HashgraphOnline/status/2107101081994137980?ref_src=twsrc%5Etfw)

Its demonstration video on X kept every malicious file on the same machine for convenience. A live attack would put the database file and the code on a server the attacker controls.

Rick de Jager of V12 reported the LibreOffice flaw, as did Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache credits Codean Labs for the OpenOffice variant. Caolán McNamara of Collabora Productivity wrote the LibreOffice fix.

## OpenOffice users are waiting on 4.1.17

LibreOffice’s [security advisories page](https://www.libreoffice.org/security/) tells users to move to **26.2.5** or **26.8.0**. Those builds also close two related Calc bugs.

CVE-2026-63266 allowed arbitrary file writes through Calc data mappings, the SQL provider and Firebird backup functionality. **CVE-2026-63267** let a linked CSV source read a local file into a sheet as the file loaded. It could also contact a host of the document’s choosing. The advisory says fixed builds now handle external data links “**under the same link update control as other links.**“

Read together, the [three CVEs](https://sqmagazine.co.uk/kev-tracker/) trace back to one habit: Calc reaching out to external sources during load, before anyone has agreed to anything. That’s the part of the design the October releases start to fence in.

Apache OpenOffice has no such update. The project told the [oss-security mailing list](https://www.openwall.com/lists/oss-security/2026/10/02/2) that a fix is expected in **4.1.17**, which is still in testing. Until then, turning off Java in OpenOffice’s settings removes the step the chain depends on, and leaving untrusted spreadsheets closed helps reduce risk further. Because the LibreOffice attack needs Java too, the same switch can serve as a stopgap on machines that can’t take the update today.

## What’s Next?

Anyone who opens spreadsheets from outside senders should check the installed version against those numbers now. Attachments are a standard lure in [phishing email campaigns](https://sqmagazine.co.uk/phishing-email-statistics/). Two gaps stay open in the published material: Apache has given no ship date for 4.1.17, and neither project says how many installs run with Java enabled.

That leaves the 4.1.17 release as the next marker for OpenOffice users. Until it lands, any OpenOffice install with Java on treats a hostile spreadsheet like a harmless one, with no warning in between.