Vulnerabilities Found in LibreOffice Calc and Apache OpenOffice Calc Could Allow Code Execution on Users’ Devices
552/69 Wednesday, October 7, 2026
Security researchers have disclosed vulnerabilities affecting LibreOffice Calc and Apache OpenOffice Calc that could allow attackers to execute Java code on a user’s device through a specially crafted spreadsheet file. The vulnerabilities are tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice. Successful exploitation requires the user to open the malicious file while Java Support is enabled in the application. Unlike macro execution, the software does not display the same type of warning before the Java code is executed. A Proof-of-Concept (PoC) exploit has already been released, although there are currently no reports of the vulnerabilities being actively exploited in the wild.
The vulnerabilities are related to Calc’s ability to link data within a spreadsheet to external data sources. An attacker can craft a document that connects to an ODB database file hosted on an external server. The database configuration can then be set to use a Java Database Connectivity (JDBC) driver loaded from a JAR file hosted on an attacker-controlled server. When the victim opens the document, the application may connect to the external data source and download the JAR file, allowing the attacker’s Java code to be executed on the victim’s device. Researchers successfully tested the PoC on both Windows and Linux, noting that the attack mechanism is not limited to a specific operating system.
LibreOffice has addressed CVE-2026-63277 in versions 26.2.5 and 26.8.0, and users are advised to update to these versions or later. Apache OpenOffice 4.1.16 and earlier versions remain affected by CVE-2026-59265, while version 4.1.17, which includes the fix, is currently available only as a Release Candidate. In the meantime, Apache recommends disabling Java Runtime Integration or avoiding documents from untrusted sources until a fully patched version can be installed.
Source https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.