LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open
EditorialBy TrustList Editorial
A crafted spreadsheet can load remote Java code with no macro prompt when Java support is on. A proof of concept is public, and the Apache fix is still in release candidate.
- Cybersecurity
- Vulnerability Management
- Office Suite
About LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open
LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open
5 October 2026: LibreOffice has patched CVE-2026-63277, a flaw that lets a crafted Calc spreadsheet load a Java database driver from a remote location and run its code as soon as the file is opened. Fixed versions are LibreOffice 26.2.5 and 26.8.0. Apache OpenOffice, which has the matching flaw as CVE-2026-59265, has no fix yet: every version up to and including 4.1.16 is affected.
Not yet independently verified. Neither advisory gives a severity score, and exploitation status comes from press reporting only. The Apache OpenOffice release date for 4.1.17 is not stated. We will update this when it can be confirmed, and remove this note.
The LibreOffice advisory, announced on 5 October, explains the route. Calc can link a cell range to an external data source and save that link in the document. A document could name a Java database driver for such a link, to be loaded from a remote location, so opening it could run Java code from there. In the fixed versions an entry in a Java class path has to be a file URL.
The Hacker News reports that the attack works only when Java support is enabled, that no warning appears of the kind users see before a macro runs, and that a proof of concept from the V12 security team is public. It found no reports of attacks in the wild. The flaw was reported independently by Rick de Jager of V12 and by Thomas Rinsma and Edoardo Geraci of Codean Labs, and Caolan McNamara of Collabora Productivity wrote the LibreOffice fix.
Apache's advisory says the OpenOffice fix is expected in 4.1.17, which is in the release candidate phase, and that OpenOffice.org versions may also be affected. Until then it tells users to switch off the Java runtime in the program settings (Tools, Options, OpenOffice, Java, then untick the option to use a Java runtime environment), or to avoid opening untrusted files at all.
LibreOffice's advisory page lists other Calc flaws announced the same day, among them data links that could read a local file into a sheet when a document loads. Anyone running 26.2.x or earlier should move to 26.2.5 rather than apply only the Java setting change.
Company profile on TrustList: The Document Foundation
Sources
- LibreOffice: security advisory CVE-2026-63277, 5 October 2026
- Apache OpenOffice: advisory CVE-2026-59265, 6 October 2026
- The Hacker News: LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings, 6 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Office Suite
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.