Malicious Spreadsheets Exploit LibreOffice & OpenOffice to Run Code Silently
A critical vulnerability in LibreOffice and Apache OpenOffice allows attackers to execute arbitrary code through maliciously crafted spreadsheets by abusing the 'database range' feature to load and run code from remote ODB files — all without triggering macro security warnings. The root problem lies in insufficient input validation and a failure to apply macro security controls consistently across all code execution pathways, not just traditional macros. LibreOffice has issued a patch (CVE-2026-63277), but Apache OpenOffice has no fix available yet, leaving a large portion of the user base exposed. This matters because office productivity suites are ubiquitous in enterprise environments, and silent code execution bypassing security prompts dramatically lowers the bar for successful phishing and document-based attacks.
Tactical Insight
Immediate actions
- Apply LibreOffice's patch for CVE-2026-63277 immediately and monitor Apache OpenOffice advisories for CVE-2026-59265 remediation.
- Disable Java support in LibreOffice and OpenOffice settings on all endpoints where Java functionality is not explicitly required.
- Block or restrict outbound connections from office suite processes to external/untrusted network resources via firewall or endpoint policy.
Configuration hardening
- Set macro security to the highest level in LibreOffice/OpenOffice and enforce this via group policy or configuration management tools.
- Prevent users from opening spreadsheets or office documents received from untrusted or external sources without sandboxed preview.
- Audit and restrict which applications are permitted to initiate outbound network connections using application-layer controls.
Detection measures
- Deploy endpoint detection and response (EDR) rules to alert on office suite processes spawning unexpected child processes or making external network calls.
- Monitor DNS and proxy logs for unusual outbound requests originating from LibreOffice or OpenOffice processes.
- Establish a vulnerability management cadence that flags unpatched open-source productivity software as a high-priority risk item.