LibreOffice has patched a Java code execution vulnerability, while Apache OpenOffice remains exposed as researchers demonstrate how malicious spreadsheets can bypass macro security warnings.
Malicious spreadsheets can execute Java code in LibreOffice Calc and Apache OpenOffice Calc without displaying the usual macro security warnings.
The vulnerabilities, tracked as CVE-2026-63277 and CVE-2026-59265, allow attacker-controlled code to run when users open specially crafted documents with Java integration enabled. LibreOffice has released fixes, but Apache OpenOffice remains vulnerable through version 4.1.16.
Researchers have demonstrated the technique publicly, although exploitation in the wild has not been confirmed. The attack exploits spreadsheet database connections rather than requiring users to approve macro execution.
How malicious spreadsheets execute Java code
In an October 5 security advisory, The Document Foundation disclosed that LibreOffice Calc could load Java database drivers from remote locations through external spreadsheet data connections.
A crafted spreadsheet can reference a remote OpenDocument Database (ODB) file configured to load a Java Database Connectivity (JDBC) driver from an attacker-controlled Java archive. Opening the document can trigger Java code execution without displaying a macro security prompt.
Researchers Rick de Jager of V12 Security and Thomas Rinsma and Edoardo Geraci of Codean Labs independently reported the vulnerability. A public proof of concept demonstrated code execution using a calculator application as a harmless payload.
The attack requires Java integration to be enabled. Thailand's Computer Emergency Response Team also documented the vulnerability on October 7, reporting successful proof-of-concept testing on Windows and Linux.
The exposure adds to concerns about untrusted files reaching vulnerable software. Recent incidents involving phishing lures disguised as business documents and a malicious HEIF upload targeting file-processing software involved different attack methods but similarly highlighted risks from untrusted content.
LibreOffice patched; OpenOffice fix still pending
LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0. The update restricts Java classpath entries to file URLs, blocking the remote driver-loading mechanism.
Apache OpenOffice's security advisory rates CVE-2026-59265 critical and identifies versions 4.1.16 and earlier as affected. Version 4.1.17 remained in the release candidate phase as of October 8, 2026.
Apache recommends disabling Java integration through Tools > Options > OpenOffice > Java and deselecting Use a Java runtime environment. Organizations unable to disable Java should avoid opening untrusted documents.
Publicly released exploits for separate WordPress remote code execution vulnerabilities further illustrate the importance of addressing disclosed security flaws before attackers can exploit them.
Organizations should also implement these safeguards:
- Patch affected applications: Deploy fixed LibreOffice versions, verify installations and track OpenOffice 4.1.17.
- Disable unnecessary Java functionality: Turn off Java integration and remove unused runtimes where business requirements permit.
- Restrict untrusted documents and network access: Filter suspicious attachments, isolate external spreadsheets and limit outbound connections.
- Enforce least-privilege access: Restrict permissions, apply application allowlisting where supported and isolate automated document-processing workloads.
- Monitor suspicious activity: Investigate unexpected Java execution and outbound network connections associated with office applications.
- Test incident response plans: Exercise endpoint isolation, evidence preservation and recovery procedures for document-based attacks.
Until Apache releases its fix, disabling Java integration remains the most direct protection against this attack path. Additional safeguards can limit exposure but do not replace patching.
Read more: A separate ClickFix campaign involving malicious ChatGPT GPTs shows how attackers can also trick users into executing malware without exploiting a software vulnerability.





