Two vulnerabilities in LibreOffice and Apache OpenOffice let a malicious spreadsheet run code on a victim’s computer without showing a macro warning. LibreOffice shipped fixes on October 5, while the Apache OpenOffice fix remains in testing and has not been released.
CVE-2026-63277 and CVE-2026-59265 Hit Two Office Suites
CVE-2026-63277 affects LibreOffice and CVE-2026-59265 affects Apache OpenOffice. Public disclosure came on October 6. The source reporting does not state CVSS scores for either flaw.
The two flaws share an attack pattern. A crafted spreadsheet reaches code execution on the machine of whoever opens it, and the office suite does not display the macro warning that normally accompanies documents capable of running code.
How Spreadsheet Database Ranges and JDBC Drivers Reach Code Execution
The attack chains spreadsheet database ranges with JDBC drivers. By combining the two, a spreadsheet can reach code execution without triggering a macro warning. The attack requires Java support to be enabled in the office suite.
The macro warning is the prompt users see when a document tries to run macros, and it is the main visible safeguard against document-borne code. A file that reaches execution through database ranges and JDBC drivers avoids that prompt entirely.
Researchers From V12 Security and Codean Labs
The vulnerabilities were found by Rick de Jager of V12 security, and by Thomas Rinsma and Edoardo Geraci of Codean Labs. The researchers demonstrated a proof of concept showing that the technique works. There are no reports of real-world attacks using either flaw.
LibreOffice 26.2.5 and 26.8.0 Carry the Fix
LibreOffice released fixed versions on October 5: 26.2.5 and 26.8.0. The affected releases are those before 26.2.5 and 26.8.0. The fixes shipped a day before public disclosure on October 6.
Apache OpenOffice 4.1.17 Is Still in Testing
Apache OpenOffice is affected up to version 4.1.16. The fixed release, version 4.1.17, is in testing and has not been released. Until it ships, OpenOffice users on 4.1.16 and earlier have no patched version to install.
Document-Borne Code Execution on Unpatched Suites
The result of the two flaws is document-borne code execution on unpatched office suites. A spreadsheet received as an attachment or downloaded from a website could carry the attack, and opening it on a system with Java support enabled could run the attacker’s code with no macro warning to alert the user.
The Java Support Condition in the Attack Path
The attack depends on Java support being enabled. Installations where Java support is turned off fall outside the attack path described by the researchers. The reporting does not say how many installations of either suite have Java enabled, so the number of exposed systems is not known.
Exploitation Status and Patch Gap
No real attacks have been reported. The researchers’ proof of concept shows the technique works, which means the method is now known, but the reporting does not link it to any observed campaign.
The two products stand in different positions. LibreOffice users can obtain version 26.2.5 or 26.8.0 now. Apache OpenOffice users face a gap until version 4.1.17 leaves testing.
Both vulnerabilities were assigned CVE identifiers, CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice, so the two suites track the flaws separately even though the underlying attack technique is shared.
Rick de Jager, Thomas Rinsma and Edoardo Geraci are the three researchers credited. Their work spans two organizations, V12 security and Codean Labs, and covers both office suites, which accounts for the separate CVE identifiers for LibreOffice and Apache OpenOffice despite the shared technique. The proof of concept they demonstrated is the only exploitation evidence described so far.
