CVE-2026-63277: LibreOffice spreadsheet runs code with no macro warning
Java JDBC classpath loaded from a remote spreadsheet link

CVE-2026-63277: LibreOffice spreadsheet runs code with no macro warning

A spreadsheet can make LibreOffice Calc run attacker code the moment it opens, with none of the warning the suite shows before a macro. The Document Foundation fixed this on 5 October as CVE-2026-63277. It only works when Java support is enabled. Researchers have shown a proof of concept. There are no reports of real attacks yet.

What happened

Calc can link a cell range to an external data source and save that link in the file. A crafted sheet points the range at a remote database document and names a Java database driver whose classpath is a jar on an attacker server. Opening the file loads that code.

The Document Foundation rates it high, CVSS 4.0 8.5. Fixed builds require a Java classpath entry to be a file URL, which blocks the remote jar. LibreOffice 26.2.5 and 26.8.0 contain the fix. Versions before those are affected.

Apache OpenOffice has the same bug as CVE-2026-59265. Every release through 4.1.16 is affected. A fix is expected in 4.1.17, which is still a release candidate.

Who is affected

  • LibreOffice users on builds older than 26.2.5 or 26.8.0, if Java is enabled.
  • Apache OpenOffice users on 4.1.16 and earlier, until 4.1.17 ships.
  • Anyone who opens spreadsheets from email or shared drives.

What to do now

Update LibreOffice to 26.2.5 or 26.8.0. On OpenOffice, turn Java off, or do not open spreadsheets you do not trust, until 4.1.17 is out.

Treat unexpected Calc attachments as executable until those updates are on the endpoint. The macro warning will not save you on an unpatched install.

Source: The Hacker News, 6 October 2026, citing The Document Foundation. LibreOffice and OpenOffice spreadsheet flaws.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-21589 lets attackers read files in 8 Atlassian products
Unauthenticated file read in self-hosted Data Center