Skip to content
Quantum Secure Labs
Cybersecurity News

A malicious spreadsheet can run code in LibreOffice and OpenOffice; only LibreOffice has a patch

A malicious spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice as soon as it is opened, with no macro warning, if Java is enabled. It affects any company using these suites. Update LibreOffice…

By Quantum Secure Labs4 min read
Hoja de cálculo abierta en la pantalla de un portátil en una oficina
In this article

A malicious spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice as soon as it is opened, with no macro warning, if Java is enabled. It affects any company using these suites. Update LibreOffice to 26.2.5 or 26.8.0; in OpenOffice, which has no patch, disable Java.

Key facts

  • LibreOffice tracks the flaw as CVE-2026-63277 and fixed it in the updates released on 5 October 2026. Versions before 26.2.5 and 26.8.0 are affected, according to The Hacker News.
  • Apache OpenOffice has the equivalent flaw, CVE-2026-59265, still unfixed. It affects every version up to 4.1.16. The fix is planned for 4.1.17, which is still in testing.
  • The attack only works with Java support enabled. It was tested on Windows and Linux, and the researchers say it does not depend on the operating system.
  • The V12 team has published a proof of concept for both programs. No real-world attacks have been reported.
  • It was found independently by Rick de Jager (V12) and by Thomas Rinsma and Edoardo Geraci (Codean Labs).

How can it run code without macros?

Because it doesn't use macros. The attack chains together legitimate Calc features, as The Hacker News explains:

  1. The sheet contains a database range that refreshes automatically when the file opens.
  2. That refresh downloads an ODB file from a web address written in the sheet.
  3. The ODB points to a Java JDBC driver hosted on a remote server.
  4. The program downloads that JAR and runs it. That code is the attacker's.

None of these steps triggers the macro warning. That is why the rule of never enabling macros does not protect you here.

Does it affect me if my company uses Microsoft Office?

The flaw is in LibreOffice and OpenOffice. It affects you if any of your machines has them installed, even if your official suite is something else. They are common on Linux machines, in companies saving on licences and in those working with the public sector. Also on laptops where someone installed one to open an .ods file. Neither updates itself, so a forgotten install stays vulnerable until someone deals with it.

Is this an emergency?

No, but it shouldn't wait until next month either. There is no known active exploitation today. The proof of concept is already public, which shortens the time until someone uses it in an email campaign with fake invoices. Update this week.

What to do today

  1. Take inventory. Find which machines have LibreOffice or OpenOffice, including those users installed themselves.
  2. Update LibreOffice to 26.2.5 or 26.8.0.
  3. In OpenOffice, disable Java under Tools > Options. Consider moving those machines to LibreOffice, which does have a patch.
  4. Warn your team. They shouldn't open spreadsheets (.ods, .xlsx) from unknown senders, especially those arriving by email or as invoices.
  5. If you don't need Java in LibreOffice, disable it there too. This is our own inference from the fact that the attack requires Java. It is not a recommendation from the sources.

What it means for a small business

The problem isn't using open-source software. It's having programs installed that nobody manages. An office suite that doesn't update itself and that nobody checks is exactly the door this flaw uses.

With OpenOffice the decision is simple: today it has no patch and LibreOffice does. If you keep OpenOffice out of habit, this is a good time to switch. If you keep it for a specific dependency, disable Java and write down why it is still there.

The second lesson is about training. Many people learned that a document is dangerous if it asks to enable macros. This attack asks for nothing. The useful rule is simpler: files from doubtful sources don't get opened until you've checked who sent them.

A transparency note: this information comes from a single secondary source. We have not been able to check the official advisories from The Document Foundation or Apache. Confirm the versions on each project's official website before updating.

If you're not sure what software runs on your machines, that inventory is the first step of any cybersecurity plan.

Frequently asked questions

Does having macros disabled protect me?

No. The attack doesn't use macros and shows no warning. What blocks it is having Java disabled or, in LibreOffice, running the fixed version.

Am I safe if I use Linux?

No. The researchers tested it on Windows and Linux and say it does not depend on the operating system.

When will OpenOffice get a patch?

The project plans the fix for version 4.1.17, which is still in testing. Until then, disable Java and don't open spreadsheets from doubtful sources.

Sources

Worried about a threat like this one?

We review your exposure and show you how to protect yourself.

See our cybersecurity service

Cybersecurity News

Warlock ransomware keeps breaching unpatched on-premises SharePoint and targets Spanish-speaking countries

Symantec warns that the Warlock ransomware group is still breaking into unpatched on-premises SharePoint servers and has hit organisations in Spanish- and Portuguese-speaking countries, including in Europe. If your…

Cybersecurity News

Fortinet warns of a critical FortiMail flaw exploited as a zero-day and still unpatched

Fortinet has confirmed attackers are already exploiting CVE-2026-104286, a critical FortiMail flaw that lets them write files to the system without authenticating. It affects the 7.2, 7.4, 7.6 and 8.0 branches, and the…

Want to apply these ideas to your business?

Tell us about your case and we'll show you how to apply these strategies to your project.