Ethical Hacking News
Recent research has exposed a new vulnerability in LibreOffice and Apache OpenOffice, allowing malicious spreadsheets to run code without any prior warnings or prompts from the user. This vulnerability can be triggered when Java support is enabled in the software, and it has the potential to be used in real attacks. Fortunately, LibreOffice has already released updates to address this issue, but Apache OpenOffice users are still at risk. To mitigate this risk, users can turn off Java in the program's settings or avoid opening spreadsheets they do not trust. Staying informed about the latest cybersecurity threats and keeping software up to date is crucial in preventing attacks like this one.
Two popular office suite software, LibreOffice and Apache OpenOffice, have a newly discovered vulnerability (CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice) that can be triggered by enabling Java support. The vulnerability can be exploited by malicious spreadsheets to run code without any prior warnings or prompts from the user. Users who rely heavily on Java functionality in their work are particularly susceptible to this type of attack. LibreOffice has already released updates to address the issue, but Apache OpenOffice users are still at risk until version 4.1.17 is released. The vulnerability works by exploiting a combination of features in Calc spreadsheets that pull in data from an outside source and refresh itself automatically. Attacks can be launched by opening a spreadsheet with a malicious ODB file that names a Java database driver and points to the attacker's code. While this vulnerability has only been shown as a proof of concept, it highlights the importance of keeping software up to date and being cautious when using everyday tools.
The world of cybersecurity has recently been shaken by the revelation of a new vulnerability in two popular office suite software, LibreOffice and Apache OpenOffice. According to recent research, these widely-used applications can be compromised by malicious spreadsheets, allowing attackers to run code without any prior warnings or prompts from the user. This discovery has sent shockwaves through the cybersecurity community, highlighting the potential risks and vulnerabilities inherent in these everyday tools.
The vulnerability in question, identified as CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice, can be triggered when the Java support is enabled in the software. This means that users who rely heavily on Java functionality in their work will be particularly susceptible to this type of attack. Fortunately, LibreOffice has already released updates to address this issue, recommending that users upgrade to version 26.2.5 or 26.8.0. However, Apache OpenOffice users are still at risk, with every version up to and including 4.1.16 affected by the vulnerability.
So, how does this vulnerability work, and what makes it so dangerous? According to recent research, the attack exploits a combination of features that are meant to be used independently but, when combined, can lead to malicious code execution without any warning to the user. This occurs when a LibreOffice or Apache OpenOffice Calc spreadsheet holds a "database range" – a block of cells that pulls in data from an outside source and refreshes itself automatically. This outside source can be a separate database file, called an ODB, that is named with a web address written into the spreadsheet. When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address.
The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver's code lives, which can be a JAR file or on a remote server. The program then downloads the JAR and starts the driver, which is the attacker's code, inside the program itself. Each of these steps is a normal feature of the software, but when they are combined, they create a security problem that can reach code execution without ever asking the user to trust the document, unlike the way the program asks before it runs a macro.
A recent proof of concept demonstrated this vulnerability, showing that the driver can open the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses. The researchers tested the attack on Windows and Linux and say it is not tied to one operating system. A real attack would instead place the database file and the code on an attacker-controlled server.
It's worth noting that this vulnerability has only been shown as a proof of concept, and there are no reports of its use in real attacks. However, this highlights the potential risks and the importance of keeping software up to date. LibreOffice has already fixed the flaw in updates released on October 5, but Apache OpenOffice has not yet addressed the matching flaw, which is expected to be fixed in version 4.1.17.
Until then, Apache OpenOffice users can block the attack by turning off Java in the program's settings or by not opening spreadsheets they do not trust. This serves as a reminder that even the most seemingly secure tools can have vulnerabilities, and it's always better to err on the side of caution.
In conclusion, the recent discovery of this vulnerability in LibreOffice and Apache OpenOffice highlights the importance of staying informed about the latest cybersecurity threats and keeping software up to date. It's a reminder that even the most everyday tools can be used as a vehicle for malicious attacks if they are not used responsibly.
Related Information:
https://www.ethicalhackingnews.com/articles/LibreOffice-and-OpenOffice-Flaws-Exposed-A-New-Frontier-in-Malicious-Spreadsheet-Attacks-ehn.shtml
https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
https://nvd.nist.gov/vuln/detail/CVE-2026-63277
https://www.cvedetails.com/cve/CVE-2026-63277/
https://nvd.nist.gov/vuln/detail/CVE-2026-59265
https://www.cvedetails.com/cve/CVE-2026-59265/
Published: Tue Oct 6 08:49:11 2026 by llama3.2 3B Q4_K_M