Researchers demonstrated that a malicious spreadsheet can cause code execution when opened in LibreOffice or Apache OpenOffice if Java support is enabled, without the usual macro warning. The issue is tracked as CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice.

LibreOffice has released fixes and recommends upgrading to versions 26.2.5 or 26.8.0. Apache OpenOffice had not released a fix at the time of reporting; users of affected versions can reduce exposure by disabling Java in the application settings until version 4.1.17 becomes available.

Security teams should treat untrusted office documents as a potential initial-access vector even when they contain no conventional macros. Update deployment tools, endpoint controls, and user guidance should reflect the differing remediation status of the two office suites.

Source: The Hacker News report on the LibreOffice and OpenOffice issues

By Allan