Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Kenya confirms first case of Ebola Bundibugyo virus

    October 6, 2026

    Former German spy chief arrested for espionage and treason

    October 6, 2026

    Money in the digital age: digital euro, tokenisation and the role of central banks

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Kenya confirms first case of Ebola Bundibugyo virus
    • Former German spy chief arrested for espionage and treason
    • Money in the digital age: digital euro, tokenisation and the role of central banks
    • Glimpse wants to give hardware companies an X-ray view of every critical part
    • Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
    • Ethereum’s proposed 3x ETF could reach CME’s futures threshold with just $362 million
    • The world’s loudest bird could drown out a rock concert
    • Far-right election results in Brazil ‘bleak’ for Indigenous peoples, says Indigenous leader
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 06, 2026Vulnerability / Open Source

    A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.

    The attack works only when the program’s Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.

    LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected.

    Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265. Every version up to and including its current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested.

    Until then, Apache OpenOffice users can block the attack by turning off Java in the program’s settings, or by not opening spreadsheets they do not trust.

    Cybersecurity

    The attack combines features that each work as intended on their own. A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a “database range”, a block of cells that pulls in data from an outside source and refreshes it by itself. That outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet.

    When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address. The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver’s code lives, which can be a JAR file, a bundle of Java code, or on a remote server. The program then downloads the JAR and starts the driver, which is the attacker’s code, inside the program itself.

    Each of these is a normal feature. The security problem, the researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.

    In the proof of concept, the driver simply opens the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses. The researchers tested the attack on Windows and Linux and say it is not tied to one operating system.

    In their demonstration, the malicious files sat on the same machine for convenience. The researchers say a real attack would instead place the database file and the code on an attacker-controlled server.

    The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache credits Codean Labs for the matching flaw in OpenOffice. The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.

    The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment.

    Code flaws LibreOffice macro Malicious OpenOffice Run Spreadsheets warnings
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

    Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

    Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

    Engineer sentenced for locking over 3,000 devices on employer network

    Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Kenya confirms first case of Ebola Bundibugyo virus

    October 6, 2026

    Former German spy chief arrested for espionage and treason

    October 6, 2026

    Money in the digital age: digital euro, tokenisation and the role of central banks

    October 6, 2026

    Glimpse wants to give hardware companies an X-ray view of every critical part

    October 6, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Kenya confirms first case of Ebola Bundibugyo virus

    October 6, 2026

    Former German spy chief arrested for espionage and treason

    October 6, 2026

    Money in the digital age: digital euro, tokenisation and the role of central banks

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.