P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

LibreOffice's fix for a spreadsheet code-execution flaw came 73 days before its advisory; OpenOffice has none

LibreOffice 26.2.5, posted on 24 July, already fixed CVE-2026-63277, a spreadsheet flaw that can run Java code on opening. The advisory followed on 5 October, 73 days later. Apache OpenOffice 4.1.16 is affected, a public proof of concept exists, and its fix is a release vote.

By Parminder Kumar Sharma · · 22 min read

Editorial illustration for the briefing: LibreOffice's fix for a spreadsheet code-execution flaw came 73 days before its advisory; OpenOffice has none

73 days between the fixed build and the advisory

The Document Foundation (TDF) posted LibreOffice 26.2.5 on 24 July 2026, in an announcement datelined 23 July. Its advisory for CVE-2026-63277, a spreadsheet that can run Java code when it is opened, is dated 5 October 2026 and says the flaw is fixed in 26.2.5 and 26.8.0. From the 26.2.5 post to the advisory is 73 days. LibreOffice 26.8.0 was announced on 26 August, 40 days before the advisory. At 14:50 BST on 6 October 2026 those two builds are 74 and 41 days old.

The Hacker News, the pointer for this briefing, says LibreOffice fixed the flaw "in updates released on October 5". The advisory was announced on 5 October. The builds that carry the fix were already on TDF's download server, so an organisation that installs updates when they appear, and not when an advisory appears, had the fix from the day the first of them shipped.

Here is what that fact does not establish.

  • It does not show exploitation. Neither project says the flaw is being exploited. CISA's SSVC entries on both CVE records read Exploitation: none, but they were stamped before the proof of concept appeared: 12:43 UTC on 5 October for LibreOffice and 03:55 UTC on 3 October for OpenOffice, against a proof of concept committed at 15:56 UTC on 5 October. KEV catalogue version 2026.10.04 lists neither CVE and no LibreOffice or OpenOffice entry at all, but it was released at 18:52 UTC on 4 October, 21 hours before the proof of concept, so it cannot speak to the days since.
  • It does not show that Java is switched on in a typical install. The attack needs Java. Neither project documents whether its Java option is on by default, and Apache says it has not bundled a Java runtime since release 3.4.
  • It does not show that the two flaws are one bug. There are two CVE identifiers, two code bases and two sets of fixes. Apache's bulletin does say that LibreOffice reported the issue as CVE-2026-63277.
  • It does not give a number of users. TDF says LibreOffice 26.8 passed 4 million downloads in September. Downloads are not users, and they say nothing about the older installs that matter here.

Two friendly names do the damage. "No macro warning" reads as if the macro prompt were the only gate between a document and the machine. In these advisories it was one gate on one door: a spreadsheet can also carry a linked data source, a documented feature, and the advisories describe that route reaching code without a macro. And "open source office suite" reads as "not a target". An unpatched Apache OpenOffice has a flaw its own project rates Critical, a public proof of concept, and a fix with no release date, only a release vote. The same shape appeared in an earlier briefing on a fix that shipped before its advisory.

What the news story says, and what the records say

The story's claims mostly hold. Two need correcting or labelling: when the fix was released, and the condition that Java be enabled. The table follows the vendor pages where they differ from the coverage.

The news story's claims against the primaries, read 6 October 2026 between 14:40 and 15:00 BST

  1. Claim in the news story
    LibreOffice fixed it in updates released on 5 October
    What the primary says
    TDF advisory, announced 5 Oct 2026: fixed in 26.2.5 and 26.8.0. TDF release posts: 26.2.5 on 24 Jul (datelined 23 Jul), 26.8.0 on 26 Aug
    Not stated
    The date the fix was committed. TDF's policy is to disclose within 30 days of resolution; the advisory gives no resolution date
  2. Claim in the news story
    It works only when Java support is enabled
    What the primary says
    Apache: switching Java off in Preferences prevents the attack. Red Hat, for LibreOffice: disabling the Java runtime in the options removes the attack vector
    Not stated
    Anything about Java being on or off in TDF's own advisory. Whether Java is on by default in either project
  3. Claim in the news story
    There is no macro-style warning
    What the primary says
    V12's repository summary says the code loads silently. TDF's fix text puts external data links under the same link update control as other links
    Not stated
    Whether any prompt appears in a given build or setting. I did not run the proof of concept
  4. Claim in the news story
    There are no reports of real attacks
    What the primary says
    CISA SSVC on both records: Exploitation none, stamped before the proof of concept. Neither CVE is in KEV 2026.10.04
    Not stated
    A statement on exploitation from TDF or Apache
  5. Claim in the news story
    OpenOffice: 4.1.16 and earlier affected, fix expected in 4.1.17
    What the primary says
    Apache bulletin: the same, with 4.1.17 in the release candidate phase. OpenOffice.org versions may also be affected
    Not stated
    A release date. A vote on 4.1.17-RC1 opened on 26 Sep for 14 days; no result in the list archive at 14:50 BST
  6. Claim in the news story
    It is the matching flaw
    What the primary says
    Apache: the LibreOffice suite reported this issue as CVE-2026-63277. The CVE records use different weakness labels, CWE-829 and CWE-426
    Not stated
    That the two share code, or that either fix would work on the other
  7. Claim in the news story
    The researchers published a proof of concept
    What the primary says
    V12's repository summary: Calc in both programs can silently load Java code from a remote database file. The commit is dated 5 Oct, 15:56 UTC
    Not stated
    A write-up from either team. Neither Codean Labs' nor V12's blog index lists one at 14:42 BST

Both projects credit the same two finders, the V12 security team and Codean Labs, who they say reported it independently. V12 sells an AI security product and says in its post that the finding came from that product, so it has a commercial interest in the publicity. That is not a reason to doubt the finding, which the two projects' own advisories confirm. It is a reason to treat the claim that an autonomous agent found it as the company's description, which neither project repeats, until a write-up shows the method. A developer at Collabora Productivity is credited with the LibreOffice fix.

One prompt, several doors

In LibreOffice Calc a cell range can be linked to an external data source, and TDF says the link is saved in the document. The Help documents the feature: a Data Provider command imports CSV, HTML and XML data from a local file or a web address into a database range, and Refresh Range updates a range from an external database. TDF's advisories show what happened when a document used that feature while it was being opened. Six advisories announced on 5 October, all fixed in 26.2.5 and 26.8.0 and all credited to Codean Labs, cover it, and the last is also credited to V12.

TDF's six data-link advisories of 5 October 2026, paraphrased from the advisories page, read 6 October at 14:41 BST

  1. CVE
    CVE-2026-63267
    What TDF says a document could do
    Read a local file into the sheet, or make a request to a host of its choosing, while loading
    TDF's fix, in brief
    External data links are updated under the same link update control as other links
  2. CVE
    CVE-2026-63268
    What TDF says a document could do
    Read a local text file into the sheet, through a link of the SQL type
    TDF's fix, in brief
    Only the csv, html and xml data providers are restored on load
  3. CVE
    CVE-2026-63266
    What TDF says a document could do
    Open an embedded database that wrote a file anywhere the user could write
    TDF's fix, in brief
    Such a database can open or create files only inside its own private directory
  4. CVE
    CVE-2026-63269
    What TDF says a document could do
    On Linux, make linked media read local files and remote addresses while loading
    TDF's fix, in brief
    Playlists naming further resources are not followed, and linked media is under link update control
  5. CVE
    CVE-2026-63270
    What TDF says a document could do
    Expand environment or settings-file values in a URL, so they could be sent to a remote server
    TDF's fix, in brief
    Places that take URLs from the document refuse internal schemes
  6. CVE
    CVE-2026-63277
    What TDF says a document could do
    Name a Java database driver to be loaded from a remote location, so opening the document could run Java code from there
    TDF's fix, in brief
    A Java class path entry has to be a file URL

Read the right-hand column. Every fix narrows what a document is allowed to point at or pull in as it loads, and the clearest is the second: external data links are now updated under the same link update control as other links in a spreadsheet. The Help describes that control: settings for automatic link updates stored in a document are ignored for security reasons, and updates are bounded by the Security settings. The inference, which the advisory does not state in so many words, is that external data links sat outside it before. For the Java flaw the fix is narrower still: a remote address no longer qualifies as a Java class path entry.

That is why the headline phrase misleads. A macro warning guards macros. An older advisory on TDF's page says LibreOffice runs macros by default only from a trusted location or if they are signed. The NCSC's macro guidance, written for Microsoft Office and silent on LibreOffice and OpenOffice, goes further and tells administrators not to rely on click-through prompts as a mitigation. The trust prompt guarded one door, and a legitimate feature opened another. The diagram draws both in words.

Two columns. Door one, a macro: the spreadsheet opens, the file carries macro code, and macro security applies. Door two, a data link: the spreadsheet opens, a cell range is linked to an outside data source, the source is fetched as the document loads, it names a Java database driver held at a remote address, and Java code runs inside the office program as the logged-in user. Below, the fixed LibreOffice behaviour and the Apache OpenOffice position.
Drawn in words from TDF's advisories of 5 October 2026, Apache's bulletin of 2 October and V12's repository summary of 5 October. No driver names, file structure or exploit steps are shown.

Apache OpenOffice's own record shows the same pattern door by door. Its 4.1.16 release, on 10 November 2025, fixed five separate routes by which remote documents loaded without a prompt: frames, OLE objects, Calc external data sources, background and bullet images, and the DDE function (CVE-2025-64401 to 64405). The external data source one is rated Moderate, and Apache notes that a proof-of-concept demonstration exists. Five prompts were added, one door at a time, in the release that this Critical flaw also affects. A control that is added per door is only as good as the list of doors. An earlier briefing made the same point about a browser, where every feature worked as documented.

73 days, and who could have known

TDF's security page says its policy is to disclose a vulnerability within 30 days of resolution of the issue. The advisory gives no resolution date, so the policy cannot be tested from the page. If the 26.2.5 build, the earliest the advisory names as fixed, is taken as the nearest proxy, 30 days after 24 July is 23 August, and the advisory came 43 days after that. The pattern is visible on the same page: seven further 26.2.5 advisories (CVE-2026-63272 to 63276, 63278 and 63279) were announced on 21 September, 59 days after the build, and the six data-link advisories on 5 October. Why TDF waited is not stated. Coordination with Apache, whose own record for the matching flaw was published on 2 October, and with distributions is a plausible reason. That is inference.

A to-scale chart from 24 July to 19 October 2026. LibreOffice 26.2.5, posted 24 July, ran 73 days before the 5 October advisory, and 26.8.0, posted 26 August, ran 40 days. The Apache OpenOffice advisory of 2 October is nearly 4 days old with no fix released. The 4.1.17-RC1 vote opened 26 September for 14 days. The public proof of concept is about 22 hours old. Cyber Essentials 14 days from the advisory ends 19 October. A line marks today, 6 October, 14:50 BST.
Dates from TDF's release posts and advisories page, Apache's bulletin and development list, V12's repository commit time and NCSC's Cyber Essentials v3.3. Read 6 October 2026. Day counts are by script.

The NCSC's update-by-default guidance anticipates this. It warns that vendors may update some vulnerabilities "silently", without public acknowledgement, so that missing an update means missing those fixes too. The 26.2.5 announcement mentions bug fixes and stability work and a change to Skia rendering. TDF's advisories page now lists 13 CVEs as fixed in 26.2.5. On its face it was a maintenance release, and an organisation waiting for a security advisory would have had no reason to treat it as anything else for 73 days. An earlier briefing on MikroTik's patch, which had already published the details made the converse point: the patch can be the disclosure.

The proof of concept is much newer than the fix. V12's repository commit is dated 15:56 UTC on 5 October (16:56 BST), and its post about it carries a time of 16:15 UTC. At 13:52 UTC on 6 October the proof of concept was 21 hours and 56 minutes old. For a LibreOffice user who updated in July or August that clock never mattered. For an OpenOffice user it started with no fix to install, and the project's advisory, with its Java mitigation, had been public for three days and 20 hours.

Is Java switched on? Neither project says

The attack needs Java. Apache says disabling its Java integration prevents it, and Red Hat's page says disabling the Java runtime in LibreOffice's options eliminates the attack vector. TDF's advisory does not mention Java being on or off; it says only that in fixed versions a Java class path entry must be a file URL. So what does each project document about the setting?

What the two projects document about Java, from their own pages read on 6 October 2026

  1. Question
    Where is the switch?
    LibreOffice
    Tools, Options, LibreOffice, Advanced: Use a Java runtime environment (Help, 26.8)
    Apache OpenOffice
    Tools, Options, OpenOffice, Java: untick Use a Java runtime environment. On macOS, OpenOffice, Preferences, OpenOffice, Java (Apache bulletin)
  2. Question
    Is it on by default?
    LibreOffice
    Not stated on the Help page I read. The Help says a prompt opens when a Java application tries to reach the hard drive
    Apache OpenOffice
    Not stated on the pages I read. The project's public configuration schema lists a deprecated Java enable value of true; I did not establish that it drives the checkbox
  3. Question
    Is a Java runtime supplied?
    LibreOffice
    Not stated. System requirements say Java is needed for certain features, but not most, notably Base. On macOS 10.10 and later a JRE is not found and a JDK is required
    Apache OpenOffice
    No. A JRE has not been packaged since release 3.4. Install notes say to install one if you need Java-dependent features, mainly Base and some wizards
  4. Question
    What differs by platform?
    LibreOffice
    The JRE must match the program's architecture. It can be overridden by an environment variable, the path or a settings file in the install folder
    Apache OpenOffice
    The Windows build is 32-bit and needs a 32-bit JRE even on 64-bit Windows
  5. Question
    What differs by packaging?
    LibreOffice
    TDF tells Linux users to install through their distribution's methods. Whether a distribution package pulls in Java was not checked: Debian's package pages sit behind a challenge I did not bypass
    Apache OpenOffice
    Debian's tracker says Apache OpenOffice is not packaged in Debian

So exposure is the product of three things: an affected build, a Java runtime the program can find, and the option left on. Only the first is easy to read off an inventory. Neither project's pages let a reader assume the other two, in either direction, and I did not test a fresh install of either. One inference follows from the two mitigations and not from any statement by the projects: a machine with no Java runtime closes the route, because both mitigations amount to taking Java away. On the Windows OpenOffice build the runtime must be 32-bit, which is a detail an inventory should capture.

OpenOffice: a vote, not a date

Apache's bulletin for CVE-2026-59265 is plain. All versions up to 4.1.16 are affected, OpenOffice.org versions may also be, the severity is Critical, and until 4.1.17 is released users should untick the Java option or avoid untrusted files. The CVE record was published at 17:34 UTC on 2 October 2026 and the announcement to the oss-security list went at 17:30 UTC. At about 14:45 BST on 6 October the download page still offered 4.1.16 as current, released on 10 November 2025: 330 days earlier.

What "in testing" means can be checked in the project's public development list. At 12:26 UTC on 26 September a project member called a vote on 4.1.17-RC1 as general availability, to stay open 14 days. That puts the earliest stated end at 10 October, a Saturday. The archive shows replies through 4 October and no result message at 13:52 UTC on 6 October. The call does not mention the flaw. From the project's public git history, the candidate's commit descends from the two patch commits the CVE record cites, which carry committer dates of 18 July and 18 September 2026, so a candidate that passes would carry the fix. That derivation is mine and not Apache's. When a passed candidate would reach the download page is not stated.

The EPSS estimate for the OpenOffice record, read on 6 October and dated 5 October, was 0.22%, at about the 12th percentile, and the LibreOffice record had no EPSS score yet. Both predate the proof of concept, so neither is a forecast of what happens next. The same caution applies to the SSVC entries. One further point is about support. Cyber Essentials defines supported software as software whose vendor commits to regular fixes and gives a future date when it will stop. TDF gives dates: 25.8 reached end of life on 12 June 2026, 116 days ago, and the 26.2 branch is supported until 30 November 2026. The OpenOffice pages I read give no end-of-support date. I draw no conclusion; an assessor would.

Who scored it, and what the 14-day rule counts

Scores and ratings by whoever assigned them, from the named pages; NVD read through its API at 13:46 UTC on 6 October 2026

  1. Source and CVE
    TDF as CNA, 63277
    Score or rating
    CVSS 4.0: 8.5 High
    Note
    Local vector, passive user interaction, exploit maturity not defined. On the CVE.org record, 5 Oct
  2. Source and CVE
    Red Hat, 63277
    Score or rating
    CVSS 3.1: 7.8, preliminary
    Note
    Local vector, user interaction required
  3. Source and CVE
    SUSE, 63277
    Score or rating
    CVSS 3.1: 7.8, rated important
    Note
    Same vector as Red Hat's
  4. Source and CVE
    Ubuntu, 63277
    Score or rating
    Priority: Medium
    Note
    Status is needs evaluation on all four LTS releases listed
  5. Source and CVE
    NVD, 63277
    Score or rating
    No NVD score
    Note
    Status Received, last modified 5 Oct at 13:16 UTC
  6. Source and CVE
    Apache as CNA, 59265
    Score or rating
    Critical, a textual rating
    Note
    In the bulletin and on the CVE.org record. No CVSS vector from Apache
  7. Source and CVE
    CISA-ADP, 59265
    Score or rating
    CVSS 3.1: 8.8 High
    Note
    Network vector, user interaction required. On the CVE.org record updated 6 Oct at 13:09 UTC, not yet in NVD
  8. Source and CVE
    NVD, 59265
    Score or rating
    No NVD score
    Note
    Status Deferred, last modified 3 Oct at 04:18 UTC

The same behaviour is local in the hands of TDF, Red Hat and SUSE and network in CISA-ADP's, which is 7.8 against 8.8. Every number is above 7.0, and TDF's own label is High and Apache's word is Critical, so the Cyber Essentials trigger is met on any reading. CISA-ADP is the NVD record's source 134c704f, not a vendor, and its score is attributed to it here.

Cyber Essentials v3.3 requires software to be updated within 14 days of release where the update fixes vulnerabilities the vendor describes as critical or high risk, where they have a CVSS v3 base score of 7 or above, or where the vendor gives no details of their level. Counting is a matter of which date you start from.

Cyber Essentials 14-day dates, by script, as at 14:50 BST on 6 October 2026

  1. Counted from
    26.2.5 posted, 24 Jul 2026
    14 days ends
    Fri 7 Aug 2026
    Position now
    60 days past
  2. Counted from
    26.8.0 posted, 26 Aug 2026
    14 days ends
    Wed 9 Sep 2026
    Position now
    27 days past
  3. Counted from
    Advisory announced, 5 Oct 2026
    14 days ends
    Mon 19 Oct 2026
    Position now
    13 days left
  4. Counted from
    OpenOffice 4.1.17 released
    14 days ends
    Not started
    Position now
    No release, no date

This is my reading, not an assessor's. Most organisations will count from 5 October, because that is when the vendor's rating appeared. But the rule's third condition covers an update whose vendor gives no details of the level of the vulnerabilities it fixes, and the 26.2.5 release post gave none. On that reading the clock for 26.2.5 ran from its release, and the first two rows are overdue. An assessor decides. The NCSC's own best-practice timescale for operating systems and applications is 7 days, which for 26.2.5 would have ended on 31 July. A rule that counts from release can be late before the advisory exists.

The UK angle: who opens these files

GOV.UK's guidance on using Open Document Formats, from the Government Digital Service and the Central Digital and Data Office and dated 18 December 2018, says the Open Standards Board selected ODF 1.2 for use across government. It gives reasons that include allowing stricter security checks to help prevent common cyber-attack scenarios, and it lists LibreOffice as an ODF tool on Mac, Windows and Linux. In the text I read it does not list Apache OpenOffice. HMRC's guidance for charities says the Gift Aid schedule spreadsheet is in OpenDocument format and tells users to open it in Microsoft Excel or LibreOffice, and its vehicle-arrival notification spreadsheets are .ods files that open in Excel or LibreOffice 3.5 or later.

Three consequences follow, and none depends on an installation count, because I found no primary source that gives one for any UK sector. First, ODS files reach UK charities and businesses from government sites by design, so a blanket block on ODS at the mail gateway would break real work. Second, the government's ODF guidance lists LibreOffice and not Apache OpenOffice, so a body following it is more likely to be on the side that has a fix, if it has updated. That is inference. Third, the rationale for choosing ODF concerns the format. The advisories here describe the behaviour of two applications. Whether the data-link feature is part of the ODF standard or an application extension is not stated in anything I read, so this flaw is not evidence for or against the policy.

My judgement, not a measurement: the organisations most exposed are those with the fewest people watching an advisory feed, such as schools and charities on older machines, small firms with a copy of OpenOffice nobody remembers installing, and anything on a Linux distribution that has not yet evaluated the CVE. The table shows where the distributions stood on 6 October.

Which build is fixed, read 6 October 2026 between 14:40 and 15:00 BST

  1. Product and build
    LibreOffice 26.8.0 and later (26.8.1 was announced on 2 Oct but delayed by mirror problems)
    Status
    Fixed
    Source
    TDF advisory; TDF release posts
  2. Product and build
    LibreOffice 26.2.5 and later (26.2.6 on 4 Sep)
    Status
    Fixed
    Source
    TDF advisory; TDF release posts
  3. Product and build
    LibreOffice 26.2.0 to 26.2.4
    Status
    Affected: the CVE record lists the 26.2 series before 26.2.5
    Source
    CVE.org record
  4. Product and build
    LibreOffice 25.8 and older
    Status
    Not listed in the CVE record. 25.8 has had no security updates since 12 Jun 2026
    Source
    CVE.org record; TDF 26.2.5 post
  5. Product and build
    Debian 13 trixie, 4:25.2.3-2+deb13u8
    Status
    Fixed by DSA-6543-1
    Source
    Debian security tracker
  6. Product and build
    Debian 12 bookworm, 4:7.4.7-1+deb12u13
    Status
    Marked vulnerable, no fix listed
    Source
    Debian security tracker
  7. Product and build
    Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS
    Status
    Needs evaluation, priority Medium
    Source
    Ubuntu CVE page
  8. Product and build
    SUSE Linux Enterprise 15 SP7
    Status
    libreoffice listed as Affected
    Source
    SUSE CVE page
  9. Product and build
    Apache OpenOffice 4.1.16 and earlier
    Status
    Affected, no fix released. 4.1.17-RC1 vote open
    Source
    Apache bulletin; development list

What to do, in the order worth doing

Take this with you

Actions, most useful first

  • Inventory every copy of LibreOffice and Apache OpenOffice with its version: installed, per-user, portable and USB copies, distribution packages, and any server that runs an office program to convert or preview uploaded files. Note which machines also have a Java runtime.
  • LibreOffice: update to 26.2.5 or later on the 26.2 branch, or 26.8.0 or later. At 14:50 BST on 6 October TDF's download page offered 26.8.0 and 26.2.6. The 26.2 branch is supported until 30 November 2026, and 25.8 and older are out of support.
  • Apache OpenOffice 4.1.16 and earlier: untick Use a Java runtime environment (Tools, Options, OpenOffice, Java; on macOS, OpenOffice, Preferences, OpenOffice, Java), or remove the Java runtime from machines that do not need Base or the wizards. Install 4.1.17 when it is released, after reading its bulletin.
  • Until OpenOffice is fixed, treat spreadsheets from outside the organisation as untrusted in OpenOffice: open them in a patched LibreOffice, another viewer or a sandbox, or not at all. Decide whether OpenOffice should stay on the estate.
  • Linux: read your distribution's tracker today and do not assume the packaged version matches TDF's numbering. On 6 October Debian listed trixie as fixed and bookworm as vulnerable, Ubuntu listed four LTS releases as needs evaluation, and SUSE listed SLE 15 SP7 as affected.
  • Where policy allows, stop office programs fetching from the internet directly, with a host firewall rule per program or a proxy that logs and denies by default. Both advisories describe code loaded from a remote location, so this should break the route even on an unpatched build. It is a defensive suggestion and not something either project documents.
  • Mail and web gateways, a judgement: quarantine or detonate inbound ODS spreadsheets for now. The database file is described as fetched from a remote address, so blocking ODB attachments adds little. HMRC's own forms are ODS, so a blanket block will break real work.
  • If you keep network logs, look for office processes making outbound connections to hosts you do not recognise at the moment a spreadsheet is opened, and for outside spreadsheets opened on affected builds since the proof of concept appeared on 5 October.
  • Tell users not to open a spreadsheet they did not expect, in LibreOffice or OpenOffice, until the machine is updated. The absence of a prompt is not evidence of safety, which is the point of this flaw.
  • Cyber Essentials: treat 19 October as the latest date for the 14-day count on LibreOffice, record why for any copy still older, and for OpenOffice record the Java mitigation and the date you will review it.

The question the 73 days leave

The facts are not in dispute. A fixed LibreOffice build existed for 73 days before anyone told its users why they needed it, and an OpenOffice candidate that appears to carry the fix is waiting on a vote, while a public proof of concept is about a day old. What decides who is exposed is not the advisory feed. It is whether an update process runs by default or waits for a reason. Cyber Essentials counts its 14 days from release, as the briefing on Debian's 1,313-CVE kernel update also found, and that assumes someone noticed the release.

If TDF had never published that advisory, which of your office suites would your update process have patched on 24 July, and which would still be waiting for a reason to move?

Sources

  1. PrimaryLibreOffice security advisories: CVE-2026-63277 and five other data-link advisories, announced 5 October 2026, fixed in 26.2.5 and 26.8.0; also the 26.2.5-only advisories of 21 SeptemberThe Document Foundationaccessed 2026-10-06
  2. PrimaryLibreOffice security policy: disclosure within 30 days of resolutionThe Document Foundationaccessed 2026-10-06
  3. PrimaryLibreOffice 26.2.5 is available for download: post dated 24 July 2026, text datelined 23 July; 25.8 end of life 12 June 2026The Document Foundationaccessed 2026-10-06
  4. PrimaryLibreOffice 26.8 announcement, 26 August 2026The Document Foundationaccessed 2026-10-06
  5. PrimaryLibreOffice 26.8.1 announcement, 2 October 2026: release delayed by mirror problems; 26.2 supported until 30 November 2026The Document Foundationaccessed 2026-10-06
  6. PrimaryLibreOffice release notes page: 26.8.0 dated 26 August 2026, 26.2.6 listed as the previous branchThe Document Foundationaccessed 2026-10-06
  7. PrimaryDownload server directory listing with file times for 26.2.5, 26.2.6, 26.8.0 and 26.8.1The Document Foundationaccessed 2026-10-06
  8. PrimaryLibreOffice 26.8 Help, Advanced options: the Java runtime settingThe Document Foundationaccessed 2026-10-06
  9. PrimaryLibreOffice 26.8 Help, Calc General options: update links when loadingThe Document Foundationaccessed 2026-10-06
  10. PrimaryLibreOffice 26.8 Help, Data Provider for SpreadsheetsThe Document Foundationaccessed 2026-10-06
  11. PrimaryLibreOffice system requirements: Java needed for certain features, notably BaseThe Document Foundationaccessed 2026-10-06
  12. PrimaryTDF blog post of 6 October 2026: LibreOffice 26.8 over 4 million downloads in SeptemberThe Document Foundationaccessed 2026-10-06
  13. PrimaryCVE.org record for CVE-2026-63277: CNA The Document Foundation, CVSS 4.0 8.5, affected 26.2 series before 26.2.5, CISA SSVC entryCVE Programaccessed 2026-10-06
  14. PrimaryCVE.org record for CVE-2026-59265: CNA Apache, Critical, CISA-ADP CVSS 3.1 8.8 and SSVC entry, patch referencesCVE Programaccessed 2026-10-06
  15. PrimarySecurity bulletin for CVE-2026-59265: affected versions, Critical, Java mitigation, 4.1.17 in the release candidate phaseApache OpenOfficeaccessed 2026-10-06
  16. PrimaryApache OpenOffice security bulletin archive: five prompt-less remote-load issues fixed in 4.1.16Apache OpenOfficeaccessed 2026-10-06
  17. PrimaryApache announcement of CVE-2026-59265, 2 October 2026Apache Software Foundation via Openwall oss-securityaccessed 2026-10-06
  18. PrimaryDownloads page: current version 4.1.16, released 10 November 2025Apache OpenOfficeaccessed 2026-10-06
  19. PrimaryVote call for 4.1.17-RC1 as GA, 26 September 2026, open for 14 days, with replies to 4 OctoberApache OpenOffice development listaccessed 2026-10-06
  20. PrimaryJava and Apache OpenOffice: what needs Java, no JRE packaged since 3.4, the option to switch it offApache OpenOfficeaccessed 2026-10-06
  21. PrimaryDownload and install instructions: a JRE is no longer packagedApache OpenOfficeaccessed 2026-10-06
  22. PrimaryNVD record for CVE-2026-63277 via the API at 13:46 UTC on 6 October 2026: status Received, no NVD scoreNIST NVDaccessed 2026-10-06
  23. PrimaryNVD record for CVE-2026-59265 via the API at 13:46 UTC on 6 October 2026: status Deferred, no NVD scoreNIST NVDaccessed 2026-10-06
  24. PrimaryKnown Exploited Vulnerabilities catalogue version 2026.10.04, released 4 October 2026 at 18:52 UTC, 1,734 entriesCISAaccessed 2026-10-06
  25. PrimaryEPSS score for CVE-2026-59265, dated 5 October 2026FIRSTaccessed 2026-10-06
  26. PrimaryV12's post of 5 October 2026 announcing the flaw and describing its tool as an autonomous AI hackerV12accessed 2026-10-06
  27. PrimaryV12 blog index at 14:42 BST on 6 October 2026: no write-up of this flaw; company statements on fundingV12accessed 2026-10-06
  28. PrimaryCodean Labs blog index at 14:42 BST on 6 October 2026: no write-up of this flawCodean Labsaccessed 2026-10-06
  29. PrimaryDebian tracker entry for CVE-2026-63277: trixie fixed, bookworm vulnerable, DSA-6543-1Debian Security Trackeraccessed 2026-10-06
  30. PrimaryUbuntu CVE page for CVE-2026-63277: needs evaluation on four LTS releases, priority MediumCanonicalaccessed 2026-10-06
  31. PrimarySUSE CVE page for CVE-2026-63277: rated important, CVSS 3.1 7.8, SLE 15 SP7 affectedSUSEaccessed 2026-10-06
  32. PrimaryRed Hat CVE page for CVE-2026-63277: preliminary CVSS 3.1 7.8, mitigation textRed Hataccessed 2026-10-06
  33. PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026, Security Update ManagementNCSCaccessed 2026-10-06
  34. PrimaryVulnerability management: update by default, best-practice timescales, silent updatesNCSCaccessed 2026-10-06
  35. PrimaryMacro security for Microsoft Office: do not rely on click-through promptsNCSCaccessed 2026-10-06
  36. PrimaryUsing Open Document Formats in your organisation: ODF 1.2 selected for government, LibreOffice listedGOV.UK, Government Digital Serviceaccessed 2026-10-06
  37. PrimaryGift Aid schedule spreadsheet guidance: ODF format, open in Excel or LibreOfficeHM Revenue and Customsaccessed 2026-10-06
  38. Reported byNews coverage of 6 October 2026 used as a pointer to the primariesThe Hacker Newsaccessed 2026-10-06

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.