TGViewer
Privacy Not A Crime Privacy Not A Crime @privacynotacrime · 671 subscribers
Post #537 92
❗️ Critical vulnerability in LibreOffice and Apache OpenOffice

There's troubling news for millions of office suite users worldwide. Security researchers have discovered a serious flaw in both LibreOffice and Apache OpenOffice that lets attackers run malicious code on your device without any warning. And here's the bad part: you don't even need to enable macros for this to work. Just opening a malicious spreadsheet file is enough.

👨‍💻 Here's how it works

The problem sits deep in how these programs handle embedded elements in spreadsheets, specifically through Java Database Connectivity (JDBC). When Java support is enabled, specially crafted files can execute attacker-controlled code silently. No pop-ups, no warnings, no second chances. The vulnerability was found independently by Rick de Jager from V12 security team, plus Thomas Rinsma and Edoardo Geraci from Codean Labs. In LibreOffice it's tracked as CVE-2026-63277, while Apache OpenOffice uses CVE-2026-59265.

🟥 Patch status varies between the two

Good news for LibreOffice users: fixes dropped on October 5, 2026. If you're running LibreOffice, update to version 26.2.5 or 26.8.0 right away. These patches also cover four other related bugs in Calc, including file write vulnerabilities and server-side request issues.

Apache OpenOffice users aren't quite as lucky. The flaw remains unpatched across all versions up to 4.1.16. A fix is reportedly coming in version 4.1.17, currently in release candidate testing, but there's no firm release date yet.

➡️ What can you do right now

If you cannot update immediately, disable Java support in the application settings. Yes, it might break some features you depend on, but it shuts down this attack vector completely. Also be careful about opening spreadsheets from unknown sources, or even from people you trust if their accounts might have been compromised.

So far, there are no confirmed cases of active exploitation in the wild. This remains a proof-of-concept threat, but that could change fast once details spread through hacker communities.

🔎 Stay ahead of the curve

Keep watching for updates from The Document Foundation and Apache Software Foundation. Security teams should consider applying additional layers of protection like sandboxing document viewers or implementing strict application controls until everyone can patch up.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Cybersecurity #ZeroDay #LibreOffice #DataProtection #InfoSec

@PrivacyNotACrime 🗽 ⌨️ Chat
  • ✍ 4
More from @privacynotacrime
  1. Oct 8, 2026Lotta talk about cars recently so here's our video called "Stop Letting Your Car Spy On Yo…
  2. Oct 8, 2026❗ CVEAlertor keeps you ahead of newly disclosed vulnerabilities Monitoring security vulner…
  3. Oct 8, 2026😍 Attackers obtained rogue HTTPS certificates for several Google domains A serious securi…
  4. Oct 7, 2026■■■■□ 🍏 Cops are able to break into locked iPhones, including those that have been reboot…
  5. Oct 7, 2026👁 Quick OSINT bot: Full analysis of features and practical intelligence use Telegram bots…
  6. Oct 6, 2026⚠️ IronChain ransomware can leave business-critical data without a reliable recovery path—…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →