LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings Swati KhandelwalOct 06, 2026Vulnerability / Open Source A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks. LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0.…
CVEs: CVE-2026-63277, CVE-2026-59265, CVE-2026-88772
Original source: thehackernews.com