importantSYS.SOURCE: The Hacker News• 2026-10-06T17:27:00+05:30
Security Flaws in LibreOffice and OpenOffice Enable Unrestricted Code Execution via Malicious Spreadsheets
Security researchers have identified vulnerabilities in LibreOffice and OpenOffice that allow malicious spreadsheets to execute arbitrary code without macro warnings, leveraging Java support. While LibreOffice has patched the flaw (CVE-2026-63277), Apache OpenOffice remains affected, with a fix pending in version 4.1.17.
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.
The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in
*** END OF TRANSMISSION ***