What Happened
Researchers found flaws in LibreOffice and Apache OpenOffice where a spreadsheet runs attacker code with no trust prompt. The Hacker News reports the attack needs Java support enabled. The spreadsheet holds a database range set to refresh from an external ODB file. The ODB file names a JDBC driver at a remote JAR file, and the application downloads and runs it.
Macro warnings never appear. V12 Security and Codean Labs found the issues independently. LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0. Apache OpenOffice CVE-2026-59265 stays open through 4.1.16, with a fix in testing for 4.1.17. A proof of concept exists. No attacks are reported yet.
Why This Matters for Canadian Organizations
Open source office suites run on desktops across Canadian schools, municipalities, and non-profits looking to cut licensing costs. Staff open spreadsheets from email all day. Security training teaches users to distrust macros. It does not teach them to distrust a data range refresh.
A successful attack gives an intruder code execution on a workstation with the user’s access to shared drives and records. For bodies subject to PIPEDA or provincial privacy law, this is a possible breach of personal information. Older OpenOffice installs are the weakest point because no patch exists.
What to Do
Update LibreOffice to 26.2.5, 26.8.0, or later. Turn off Java support in LibreOffice and OpenOffice unless a business process needs it. Move OpenOffice users to a maintained suite where possible. Block outbound requests to unknown hosts from office applications. Treat spreadsheets from outside your organization as untrusted. Find related guidance in our TechTalk coverage.






