Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Two separate office-suite advisories describe Java-related code-execution risks when a crafted document is opened. Apache OpenOffice’s CVE-2026-59265 affects versions through 4.1.16; Apache’s advisory says 4.1.17 is expected to fix it and was in release-candidate phase. LibreOffice’s distinct CVE-2026-63277 concerns Calc external data sources and lists fixes in versions 26.2.5 and 26.8.0. Neither advisory means every spreadsheet—or every current installation—is vulnerable.

What the two advisories actually say

The headline phrase “malicious spreadsheets run code without macro warnings” overstates what the advisories establish. The Apache advisory refers to a crafted, untrusted document opened by a user. LibreOffice’s advisory describes a Calc document that links a cell range to an external data source. The two issues have different code paths, affected-version information, and remediation.

Apache’s OpenOffice Security Team describes CVE-2026-59265 this way: “A code execution issue in the Java integration in Apache OpenOffice allows a crafted untrusted document to trigger the execution of arbitrary, even remote, code when it is opened by the user.” Apache rates the issue Critical, but the advisory page does not provide a numerical CVSS score. Read Apache’s CVE-2026-59265 advisory.

Suite and issue What triggers it Affected versions and fix status What to do
Apache OpenOffice CVE-2026-59265 Opening a crafted untrusted document can trigger Java integration to execute code, including remote code. Apache lists versions through 4.1.16 as affected. Its advisory says 4.1.17 is expected to fix the issue and was in release-candidate phase. Disable Java runtime integration as an interim measure; if you cannot, avoid opening untrusted files. Upgrade to the fixed version when Apache releases it.
LibreOffice CVE-2026-63277 A Calc document can link a cell range to an external data source and specify a Java database driver loaded remotely, allowing Java code to run when the document is opened. The Document Foundation lists fixes in LibreOffice 26.2.5 and 26.8.0. Upgrade to the applicable fixed LibreOffice version.

The version and fix statements above reflect the advisories cited here; check the linked advisories for any subsequent release-status updates before deciding whether a particular installation is current.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to reduce the OpenOffice risk now

Disable Java integration

Apache’s interim mitigation is to turn off the Java runtime integration. In OpenOffice on Windows or Linux, use Tools > Options > OpenOffice > Java, then clear Use a Java runtime environment. On macOS, use OpenOffice > Preferences > OpenOffice > Java and clear the same setting. Apache says this prevents the attack described in CVE-2026-59265. Some features that depend on Java may stop working while the setting is disabled.

If Java cannot be disabled

Apache advises avoiding untrusted files if you cannot turn off Java integration. In practice, do not open unexpected spreadsheets or office documents from email, messaging apps, or unfamiliar download sites until you can verify the sender and expected file. A familiar file extension does not establish that a document is safe.

Install the OpenOffice fix when available

Apache’s advisory identifies 4.1.17 as the expected fix, but describes it as in release-candidate phase. Do not treat that advisory wording as confirmation that the final release is available. Check Apache’s Security Team Bulletin and the CVE advisory for updated release information; install the fixed release when Apache marks it available.

What LibreOffice users should do

LibreOffice tracks CVE-2026-63277 separately from the OpenOffice issue. The Document Foundation says the affected Calc behavior involves an external data source and a Java database driver that can be loaded remotely. Its advisory lists fixes in versions 26.2.5 and 26.8.0. Use the fixed version corresponding to your LibreOffice branch, or a later version that includes the fix. See the LibreOffice CVE-2026-63277 advisory for the Foundation’s details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The two vulnerabilities share credited researchers, but that does not make them one flaw or mean OpenOffice’s Java setting is the stated remedy for LibreOffice. Follow each suite’s own advisory and update guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why older spreadsheet security headlines may describe something else

Calc has had other security advisories involving formulas, macros, Java, external data, or DDE links. Similar wording in a headline does not mean those issues share the same trigger or remain unpatched.

  • OpenOffice CVE-2025-64403: Calc external data sources could load without a prompt in versions through 4.1.15; the advisory says the issue was fixed in 4.1.16. Apache’s CVE-2025-64403 advisory says there were no known exploits of that vulnerability and notes a proof-of-concept demonstration.
  • OpenOffice CVE-2025-64405: A separate Calc DDE-link issue could load content without a prompt. The advisory covers versions through 4.1.15 and advises upgrading to 4.1.16. Its statements about known exploits and a proof of concept apply to this CVE, not the current Java issue. Apache’s CVE-2025-64405 advisory.
  • Other LibreOffice issues: The Foundation’s archive lists earlier, distinct issues involving a malformed Calc formula parameter, macro URL execution, and Java class-path behavior. Their existence does not show that they remain unpatched or that they are the same as CVE-2026-63277. See LibreOffice security advisories.

Apache also published CVE-2025-64407, another separate OpenOffice advisory. It should not be confused with CVE-2026-59265. Apache’s CVE-2025-64407 advisory.

What this means when opening a spreadsheet

  • These advisories do not establish that all spreadsheets, all documents, or every installation of either suite can execute code.
  • The documented triggers involve crafted documents and Java-related behavior—not simply opening any spreadsheet or using a macro.
  • For OpenOffice, the advisory’s affected range and interim mitigation are specific: versions through 4.1.16, with Java integration disabled as the temporary defense.
  • For LibreOffice, install a version containing the CVE-2026-63277 fix; the Foundation lists 26.2.5 and 26.8.0.
  • Older vulnerability disclosures, including any statements about proof-of-concept demonstrations or known exploits, apply only to their named CVEs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.