The Hacker News reported on 6 October that a booby-trapped spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice. The code starts as soon as the file opens. Neither program shows the warning it gives before running a macro. LibreOffice fixed its flaw, CVE-2026-63277, in updates released on 5 October. It recommends versions 26.2.5 or 26.8.0. Apache OpenOffice tracks its flaw as CVE-2026-59265 and has not fixed it. Every version up to and including 4.1.16 is affected.
The attack works only when Java support is switched on. The Hacker News said it has so far been shown only as a proof of concept, with no reports of real attacks. The researchers' demo just opened the Calculator app, but they say the same route can run any Java code. The OpenOffice project expects a fix in version 4.1.17, which is still in testing. No release date was given. The Hacker News said it has asked The Document Foundation and the OpenOffice project for comment. Their answers are not yet known.
Teams with either office suite on staff computers can check which version they run. LibreOffice users need 26.2.5 or 26.8.0, while OpenOffice users can currently rely only on turning off Java or avoiding spreadsheets they do not trust.