LibreOffice's fix for a spreadsheet code-execution flaw came 73 days before its advisory; OpenOffice has none
LibreOffice 26.2.5, posted on 24 July, already fixed CVE-2026-63277, a spreadsheet flaw that can run Java code on opening. The advisory followed on 5 October, 73 days later. Apache OpenOffice 4.1.16 is affected, a public proof of concept exists, and its fix is a release vote.
By Parminder Kumar Sharma · · 22 min read

73 days between the fixed build and the advisory
The Document Foundation (TDF) posted LibreOffice 26.2.5 on 24 July 2026, in an announcement datelined 23 July. Its advisory for CVE-2026-63277, a spreadsheet that can run Java code when it is opened, is dated 5 October 2026 and says the flaw is fixed in 26.2.5 and 26.8.0. From the 26.2.5 post to the advisory is 73 days. LibreOffice 26.8.0 was announced on 26 August, 40 days before the advisory. At 14:50 BST on 6 October 2026 those two builds are 74 and 41 days old.
The Hacker News, the pointer for this briefing, says LibreOffice fixed the flaw "in updates released on October 5". The advisory was announced on 5 October. The builds that carry the fix were already on TDF's download server, so an organisation that installs updates when they appear, and not when an advisory appears, had the fix from the day the first of them shipped.
Here is what that fact does not establish.
- It does not show exploitation. Neither project says the flaw is being exploited. CISA's SSVC entries on both CVE records read Exploitation: none, but they were stamped before the proof of concept appeared: 12:43 UTC on 5 October for LibreOffice and 03:55 UTC on 3 October for OpenOffice, against a proof of concept committed at 15:56 UTC on 5 October. KEV catalogue version 2026.10.04 lists neither CVE and no LibreOffice or OpenOffice entry at all, but it was released at 18:52 UTC on 4 October, 21 hours before the proof of concept, so it cannot speak to the days since.
- It does not show that Java is switched on in a typical install. The attack needs Java. Neither project documents whether its Java option is on by default, and Apache says it has not bundled a Java runtime since release 3.4.
- It does not show that the two flaws are one bug. There are two CVE identifiers, two code bases and two sets of fixes. Apache's bulletin does say that LibreOffice reported the issue as CVE-2026-63277.
- It does not give a number of users. TDF says LibreOffice 26.8 passed 4 million downloads in September. Downloads are not users, and they say nothing about the older installs that matter here.
Two friendly names do the damage. "No macro warning" reads as if the macro prompt were the only gate between a document and the machine. In these advisories it was one gate on one door: a spreadsheet can also carry a linked data source, a documented feature, and the advisories describe that route reaching code without a macro. And "open source office suite" reads as "not a target". An unpatched Apache OpenOffice has a flaw its own project rates Critical, a public proof of concept, and a fix with no release date, only a release vote. The same shape appeared in an earlier briefing on a fix that shipped before its advisory.
What the news story says, and what the records say
The story's claims mostly hold. Two need correcting or labelling: when the fix was released, and the condition that Java be enabled. The table follows the vendor pages where they differ from the coverage.
The news story's claims against the primaries, read 6 October 2026 between 14:40 and 15:00 BST
- Claim in the news story
- LibreOffice fixed it in updates released on 5 October
- What the primary says
- TDF advisory, announced 5 Oct 2026: fixed in 26.2.5 and 26.8.0. TDF release posts: 26.2.5 on 24 Jul (datelined 23 Jul), 26.8.0 on 26 Aug
- Not stated
- The date the fix was committed. TDF's policy is to disclose within 30 days of resolution; the advisory gives no resolution date
- Claim in the news story
- It works only when Java support is enabled
- What the primary says
- Apache: switching Java off in Preferences prevents the attack. Red Hat, for LibreOffice: disabling the Java runtime in the options removes the attack vector
- Not stated
- Anything about Java being on or off in TDF's own advisory. Whether Java is on by default in either project
- Claim in the news story
- There is no macro-style warning
- What the primary says
- V12's repository summary says the code loads silently. TDF's fix text puts external data links under the same link update control as other links
- Not stated
- Whether any prompt appears in a given build or setting. I did not run the proof of concept
- Claim in the news story
- There are no reports of real attacks
- What the primary says
- CISA SSVC on both records: Exploitation none, stamped before the proof of concept. Neither CVE is in KEV 2026.10.04
- Not stated
- A statement on exploitation from TDF or Apache
- Claim in the news story
- OpenOffice: 4.1.16 and earlier affected, fix expected in 4.1.17
- What the primary says
- Apache bulletin: the same, with 4.1.17 in the release candidate phase. OpenOffice.org versions may also be affected
- Not stated
- A release date. A vote on 4.1.17-RC1 opened on 26 Sep for 14 days; no result in the list archive at 14:50 BST
- Claim in the news story
- It is the matching flaw
- What the primary says
- Apache: the LibreOffice suite reported this issue as CVE-2026-63277. The CVE records use different weakness labels, CWE-829 and CWE-426
- Not stated
- That the two share code, or that either fix would work on the other
- Claim in the news story
- The researchers published a proof of concept
- What the primary says
- V12's repository summary: Calc in both programs can silently load Java code from a remote database file. The commit is dated 5 Oct, 15:56 UTC
- Not stated
- A write-up from either team. Neither Codean Labs' nor V12's blog index lists one at 14:42 BST
| Claim in the news story | What the primary says | Not stated |
|---|---|---|
| LibreOffice fixed it in updates released on 5 October | TDF advisory, announced 5 Oct 2026: fixed in 26.2.5 and 26.8.0. TDF release posts: 26.2.5 on 24 Jul (datelined 23 Jul), 26.8.0 on 26 Aug | The date the fix was committed. TDF's policy is to disclose within 30 days of resolution; the advisory gives no resolution date |
| It works only when Java support is enabled | Apache: switching Java off in Preferences prevents the attack. Red Hat, for LibreOffice: disabling the Java runtime in the options removes the attack vector | Anything about Java being on or off in TDF's own advisory. Whether Java is on by default in either project |
| There is no macro-style warning | V12's repository summary says the code loads silently. TDF's fix text puts external data links under the same link update control as other links | Whether any prompt appears in a given build or setting. I did not run the proof of concept |
| There are no reports of real attacks | CISA SSVC on both records: Exploitation none, stamped before the proof of concept. Neither CVE is in KEV 2026.10.04 | A statement on exploitation from TDF or Apache |
| OpenOffice: 4.1.16 and earlier affected, fix expected in 4.1.17 | Apache bulletin: the same, with 4.1.17 in the release candidate phase. OpenOffice.org versions may also be affected | A release date. A vote on 4.1.17-RC1 opened on 26 Sep for 14 days; no result in the list archive at 14:50 BST |
| It is the matching flaw | Apache: the LibreOffice suite reported this issue as CVE-2026-63277. The CVE records use different weakness labels, CWE-829 and CWE-426 | That the two share code, or that either fix would work on the other |
| The researchers published a proof of concept | V12's repository summary: Calc in both programs can silently load Java code from a remote database file. The commit is dated 5 Oct, 15:56 UTC | A write-up from either team. Neither Codean Labs' nor V12's blog index lists one at 14:42 BST |
Both projects credit the same two finders, the V12 security team and Codean Labs, who they say reported it independently. V12 sells an AI security product and says in its post that the finding came from that product, so it has a commercial interest in the publicity. That is not a reason to doubt the finding, which the two projects' own advisories confirm. It is a reason to treat the claim that an autonomous agent found it as the company's description, which neither project repeats, until a write-up shows the method. A developer at Collabora Productivity is credited with the LibreOffice fix.
One prompt, several doors
In LibreOffice Calc a cell range can be linked to an external data source, and TDF says the link is saved in the document. The Help documents the feature: a Data Provider command imports CSV, HTML and XML data from a local file or a web address into a database range, and Refresh Range updates a range from an external database. TDF's advisories show what happened when a document used that feature while it was being opened. Six advisories announced on 5 October, all fixed in 26.2.5 and 26.8.0 and all credited to Codean Labs, cover it, and the last is also credited to V12.
TDF's six data-link advisories of 5 October 2026, paraphrased from the advisories page, read 6 October at 14:41 BST
- CVE
- CVE-2026-63267
- What TDF says a document could do
- Read a local file into the sheet, or make a request to a host of its choosing, while loading
- TDF's fix, in brief
- External data links are updated under the same link update control as other links
- CVE
- CVE-2026-63268
- What TDF says a document could do
- Read a local text file into the sheet, through a link of the SQL type
- TDF's fix, in brief
- Only the csv, html and xml data providers are restored on load
- CVE
- CVE-2026-63266
- What TDF says a document could do
- Open an embedded database that wrote a file anywhere the user could write
- TDF's fix, in brief
- Such a database can open or create files only inside its own private directory
- CVE
- CVE-2026-63269
- What TDF says a document could do
- On Linux, make linked media read local files and remote addresses while loading
- TDF's fix, in brief
- Playlists naming further resources are not followed, and linked media is under link update control
- CVE
- CVE-2026-63270
- What TDF says a document could do
- Expand environment or settings-file values in a URL, so they could be sent to a remote server
- TDF's fix, in brief
- Places that take URLs from the document refuse internal schemes
- CVE
- CVE-2026-63277
- What TDF says a document could do
- Name a Java database driver to be loaded from a remote location, so opening the document could run Java code from there
- TDF's fix, in brief
- A Java class path entry has to be a file URL
| CVE | What TDF says a document could do | TDF's fix, in brief |
|---|---|---|
| CVE-2026-63267 | Read a local file into the sheet, or make a request to a host of its choosing, while loading | External data links are updated under the same link update control as other links |
| CVE-2026-63268 | Read a local text file into the sheet, through a link of the SQL type | Only the csv, html and xml data providers are restored on load |
| CVE-2026-63266 | Open an embedded database that wrote a file anywhere the user could write | Such a database can open or create files only inside its own private directory |
| CVE-2026-63269 | On Linux, make linked media read local files and remote addresses while loading | Playlists naming further resources are not followed, and linked media is under link update control |
| CVE-2026-63270 | Expand environment or settings-file values in a URL, so they could be sent to a remote server | Places that take URLs from the document refuse internal schemes |
| CVE-2026-63277 | Name a Java database driver to be loaded from a remote location, so opening the document could run Java code from there | A Java class path entry has to be a file URL |
Read the right-hand column. Every fix narrows what a document is allowed to point at or pull in as it loads, and the clearest is the second: external data links are now updated under the same link update control as other links in a spreadsheet. The Help describes that control: settings for automatic link updates stored in a document are ignored for security reasons, and updates are bounded by the Security settings. The inference, which the advisory does not state in so many words, is that external data links sat outside it before. For the Java flaw the fix is narrower still: a remote address no longer qualifies as a Java class path entry.
That is why the headline phrase misleads. A macro warning guards macros. An older advisory on TDF's page says LibreOffice runs macros by default only from a trusted location or if they are signed. The NCSC's macro guidance, written for Microsoft Office and silent on LibreOffice and OpenOffice, goes further and tells administrators not to rely on click-through prompts as a mitigation. The trust prompt guarded one door, and a legitimate feature opened another. The diagram draws both in words.
Apache OpenOffice's own record shows the same pattern door by door. Its 4.1.16 release, on 10 November 2025, fixed five separate routes by which remote documents loaded without a prompt: frames, OLE objects, Calc external data sources, background and bullet images, and the DDE function (CVE-2025-64401 to 64405). The external data source one is rated Moderate, and Apache notes that a proof-of-concept demonstration exists. Five prompts were added, one door at a time, in the release that this Critical flaw also affects. A control that is added per door is only as good as the list of doors. An earlier briefing made the same point about a browser, where every feature worked as documented.
73 days, and who could have known
TDF's security page says its policy is to disclose a vulnerability within 30 days of resolution of the issue. The advisory gives no resolution date, so the policy cannot be tested from the page. If the 26.2.5 build, the earliest the advisory names as fixed, is taken as the nearest proxy, 30 days after 24 July is 23 August, and the advisory came 43 days after that. The pattern is visible on the same page: seven further 26.2.5 advisories (CVE-2026-63272 to 63276, 63278 and 63279) were announced on 21 September, 59 days after the build, and the six data-link advisories on 5 October. Why TDF waited is not stated. Coordination with Apache, whose own record for the matching flaw was published on 2 October, and with distributions is a plausible reason. That is inference.
The NCSC's update-by-default guidance anticipates this. It warns that vendors may update some vulnerabilities "silently", without public acknowledgement, so that missing an update means missing those fixes too. The 26.2.5 announcement mentions bug fixes and stability work and a change to Skia rendering. TDF's advisories page now lists 13 CVEs as fixed in 26.2.5. On its face it was a maintenance release, and an organisation waiting for a security advisory would have had no reason to treat it as anything else for 73 days. An earlier briefing on MikroTik's patch, which had already published the details made the converse point: the patch can be the disclosure.
The proof of concept is much newer than the fix. V12's repository commit is dated 15:56 UTC on 5 October (16:56 BST), and its post about it carries a time of 16:15 UTC. At 13:52 UTC on 6 October the proof of concept was 21 hours and 56 minutes old. For a LibreOffice user who updated in July or August that clock never mattered. For an OpenOffice user it started with no fix to install, and the project's advisory, with its Java mitigation, had been public for three days and 20 hours.
Is Java switched on? Neither project says
The attack needs Java. Apache says disabling its Java integration prevents it, and Red Hat's page says disabling the Java runtime in LibreOffice's options eliminates the attack vector. TDF's advisory does not mention Java being on or off; it says only that in fixed versions a Java class path entry must be a file URL. So what does each project document about the setting?
What the two projects document about Java, from their own pages read on 6 October 2026
- Question
- Where is the switch?
- LibreOffice
- Tools, Options, LibreOffice, Advanced: Use a Java runtime environment (Help, 26.8)
- Apache OpenOffice
- Tools, Options, OpenOffice, Java: untick Use a Java runtime environment. On macOS, OpenOffice, Preferences, OpenOffice, Java (Apache bulletin)
- Question
- Is it on by default?
- LibreOffice
- Not stated on the Help page I read. The Help says a prompt opens when a Java application tries to reach the hard drive
- Apache OpenOffice
- Not stated on the pages I read. The project's public configuration schema lists a deprecated Java enable value of true; I did not establish that it drives the checkbox
- Question
- Is a Java runtime supplied?
- LibreOffice
- Not stated. System requirements say Java is needed for certain features, but not most, notably Base. On macOS 10.10 and later a JRE is not found and a JDK is required
- Apache OpenOffice
- No. A JRE has not been packaged since release 3.4. Install notes say to install one if you need Java-dependent features, mainly Base and some wizards
- Question
- What differs by platform?
- LibreOffice
- The JRE must match the program's architecture. It can be overridden by an environment variable, the path or a settings file in the install folder
- Apache OpenOffice
- The Windows build is 32-bit and needs a 32-bit JRE even on 64-bit Windows
- Question
- What differs by packaging?
- LibreOffice
- TDF tells Linux users to install through their distribution's methods. Whether a distribution package pulls in Java was not checked: Debian's package pages sit behind a challenge I did not bypass
- Apache OpenOffice
- Debian's tracker says Apache OpenOffice is not packaged in Debian
| Question | LibreOffice | Apache OpenOffice |
|---|---|---|
| Where is the switch? | Tools, Options, LibreOffice, Advanced: Use a Java runtime environment (Help, 26.8) | Tools, Options, OpenOffice, Java: untick Use a Java runtime environment. On macOS, OpenOffice, Preferences, OpenOffice, Java (Apache bulletin) |
| Is it on by default? | Not stated on the Help page I read. The Help says a prompt opens when a Java application tries to reach the hard drive | Not stated on the pages I read. The project's public configuration schema lists a deprecated Java enable value of true; I did not establish that it drives the checkbox |
| Is a Java runtime supplied? | Not stated. System requirements say Java is needed for certain features, but not most, notably Base. On macOS 10.10 and later a JRE is not found and a JDK is required | No. A JRE has not been packaged since release 3.4. Install notes say to install one if you need Java-dependent features, mainly Base and some wizards |
| What differs by platform? | The JRE must match the program's architecture. It can be overridden by an environment variable, the path or a settings file in the install folder | The Windows build is 32-bit and needs a 32-bit JRE even on 64-bit Windows |
| What differs by packaging? | TDF tells Linux users to install through their distribution's methods. Whether a distribution package pulls in Java was not checked: Debian's package pages sit behind a challenge I did not bypass | Debian's tracker says Apache OpenOffice is not packaged in Debian |
So exposure is the product of three things: an affected build, a Java runtime the program can find, and the option left on. Only the first is easy to read off an inventory. Neither project's pages let a reader assume the other two, in either direction, and I did not test a fresh install of either. One inference follows from the two mitigations and not from any statement by the projects: a machine with no Java runtime closes the route, because both mitigations amount to taking Java away. On the Windows OpenOffice build the runtime must be 32-bit, which is a detail an inventory should capture.
OpenOffice: a vote, not a date
Apache's bulletin for CVE-2026-59265 is plain. All versions up to 4.1.16 are affected, OpenOffice.org versions may also be, the severity is Critical, and until 4.1.17 is released users should untick the Java option or avoid untrusted files. The CVE record was published at 17:34 UTC on 2 October 2026 and the announcement to the oss-security list went at 17:30 UTC. At about 14:45 BST on 6 October the download page still offered 4.1.16 as current, released on 10 November 2025: 330 days earlier.
What "in testing" means can be checked in the project's public development list. At 12:26 UTC on 26 September a project member called a vote on 4.1.17-RC1 as general availability, to stay open 14 days. That puts the earliest stated end at 10 October, a Saturday. The archive shows replies through 4 October and no result message at 13:52 UTC on 6 October. The call does not mention the flaw. From the project's public git history, the candidate's commit descends from the two patch commits the CVE record cites, which carry committer dates of 18 July and 18 September 2026, so a candidate that passes would carry the fix. That derivation is mine and not Apache's. When a passed candidate would reach the download page is not stated.
The EPSS estimate for the OpenOffice record, read on 6 October and dated 5 October, was 0.22%, at about the 12th percentile, and the LibreOffice record had no EPSS score yet. Both predate the proof of concept, so neither is a forecast of what happens next. The same caution applies to the SSVC entries. One further point is about support. Cyber Essentials defines supported software as software whose vendor commits to regular fixes and gives a future date when it will stop. TDF gives dates: 25.8 reached end of life on 12 June 2026, 116 days ago, and the 26.2 branch is supported until 30 November 2026. The OpenOffice pages I read give no end-of-support date. I draw no conclusion; an assessor would.
Who scored it, and what the 14-day rule counts
Scores and ratings by whoever assigned them, from the named pages; NVD read through its API at 13:46 UTC on 6 October 2026
- Source and CVE
- TDF as CNA, 63277
- Score or rating
- CVSS 4.0: 8.5 High
- Note
- Local vector, passive user interaction, exploit maturity not defined. On the CVE.org record, 5 Oct
- Source and CVE
- Red Hat, 63277
- Score or rating
- CVSS 3.1: 7.8, preliminary
- Note
- Local vector, user interaction required
- Source and CVE
- SUSE, 63277
- Score or rating
- CVSS 3.1: 7.8, rated important
- Note
- Same vector as Red Hat's
- Source and CVE
- Ubuntu, 63277
- Score or rating
- Priority: Medium
- Note
- Status is needs evaluation on all four LTS releases listed
- Source and CVE
- NVD, 63277
- Score or rating
- No NVD score
- Note
- Status Received, last modified 5 Oct at 13:16 UTC
- Source and CVE
- Apache as CNA, 59265
- Score or rating
- Critical, a textual rating
- Note
- In the bulletin and on the CVE.org record. No CVSS vector from Apache
- Source and CVE
- CISA-ADP, 59265
- Score or rating
- CVSS 3.1: 8.8 High
- Note
- Network vector, user interaction required. On the CVE.org record updated 6 Oct at 13:09 UTC, not yet in NVD
- Source and CVE
- NVD, 59265
- Score or rating
- No NVD score
- Note
- Status Deferred, last modified 3 Oct at 04:18 UTC
| Source and CVE | Score or rating | Note |
|---|---|---|
| TDF as CNA, 63277 | CVSS 4.0: 8.5 High | Local vector, passive user interaction, exploit maturity not defined. On the CVE.org record, 5 Oct |
| Red Hat, 63277 | CVSS 3.1: 7.8, preliminary | Local vector, user interaction required |
| SUSE, 63277 | CVSS 3.1: 7.8, rated important | Same vector as Red Hat's |
| Ubuntu, 63277 | Priority: Medium | Status is needs evaluation on all four LTS releases listed |
| NVD, 63277 | No NVD score | Status Received, last modified 5 Oct at 13:16 UTC |
| Apache as CNA, 59265 | Critical, a textual rating | In the bulletin and on the CVE.org record. No CVSS vector from Apache |
| CISA-ADP, 59265 | CVSS 3.1: 8.8 High | Network vector, user interaction required. On the CVE.org record updated 6 Oct at 13:09 UTC, not yet in NVD |
| NVD, 59265 | No NVD score | Status Deferred, last modified 3 Oct at 04:18 UTC |
The same behaviour is local in the hands of TDF, Red Hat and SUSE and network in CISA-ADP's, which is 7.8 against 8.8. Every number is above 7.0, and TDF's own label is High and Apache's word is Critical, so the Cyber Essentials trigger is met on any reading. CISA-ADP is the NVD record's source 134c704f, not a vendor, and its score is attributed to it here.
Cyber Essentials v3.3 requires software to be updated within 14 days of release where the update fixes vulnerabilities the vendor describes as critical or high risk, where they have a CVSS v3 base score of 7 or above, or where the vendor gives no details of their level. Counting is a matter of which date you start from.
Cyber Essentials 14-day dates, by script, as at 14:50 BST on 6 October 2026
- Counted from
- 26.2.5 posted, 24 Jul 2026
- 14 days ends
- Fri 7 Aug 2026
- Position now
- 60 days past
- Counted from
- 26.8.0 posted, 26 Aug 2026
- 14 days ends
- Wed 9 Sep 2026
- Position now
- 27 days past
- Counted from
- Advisory announced, 5 Oct 2026
- 14 days ends
- Mon 19 Oct 2026
- Position now
- 13 days left
- Counted from
- OpenOffice 4.1.17 released
- 14 days ends
- Not started
- Position now
- No release, no date
| Counted from | 14 days ends | Position now |
|---|---|---|
| 26.2.5 posted, 24 Jul 2026 | Fri 7 Aug 2026 | 60 days past |
| 26.8.0 posted, 26 Aug 2026 | Wed 9 Sep 2026 | 27 days past |
| Advisory announced, 5 Oct 2026 | Mon 19 Oct 2026 | 13 days left |
| OpenOffice 4.1.17 released | Not started | No release, no date |
This is my reading, not an assessor's. Most organisations will count from 5 October, because that is when the vendor's rating appeared. But the rule's third condition covers an update whose vendor gives no details of the level of the vulnerabilities it fixes, and the 26.2.5 release post gave none. On that reading the clock for 26.2.5 ran from its release, and the first two rows are overdue. An assessor decides. The NCSC's own best-practice timescale for operating systems and applications is 7 days, which for 26.2.5 would have ended on 31 July. A rule that counts from release can be late before the advisory exists.
The UK angle: who opens these files
GOV.UK's guidance on using Open Document Formats, from the Government Digital Service and the Central Digital and Data Office and dated 18 December 2018, says the Open Standards Board selected ODF 1.2 for use across government. It gives reasons that include allowing stricter security checks to help prevent common cyber-attack scenarios, and it lists LibreOffice as an ODF tool on Mac, Windows and Linux. In the text I read it does not list Apache OpenOffice. HMRC's guidance for charities says the Gift Aid schedule spreadsheet is in OpenDocument format and tells users to open it in Microsoft Excel or LibreOffice, and its vehicle-arrival notification spreadsheets are .ods files that open in Excel or LibreOffice 3.5 or later.
Three consequences follow, and none depends on an installation count, because I found no primary source that gives one for any UK sector. First, ODS files reach UK charities and businesses from government sites by design, so a blanket block on ODS at the mail gateway would break real work. Second, the government's ODF guidance lists LibreOffice and not Apache OpenOffice, so a body following it is more likely to be on the side that has a fix, if it has updated. That is inference. Third, the rationale for choosing ODF concerns the format. The advisories here describe the behaviour of two applications. Whether the data-link feature is part of the ODF standard or an application extension is not stated in anything I read, so this flaw is not evidence for or against the policy.
My judgement, not a measurement: the organisations most exposed are those with the fewest people watching an advisory feed, such as schools and charities on older machines, small firms with a copy of OpenOffice nobody remembers installing, and anything on a Linux distribution that has not yet evaluated the CVE. The table shows where the distributions stood on 6 October.
Which build is fixed, read 6 October 2026 between 14:40 and 15:00 BST
- Product and build
- LibreOffice 26.8.0 and later (26.8.1 was announced on 2 Oct but delayed by mirror problems)
- Status
- Fixed
- Source
- TDF advisory; TDF release posts
- Product and build
- LibreOffice 26.2.5 and later (26.2.6 on 4 Sep)
- Status
- Fixed
- Source
- TDF advisory; TDF release posts
- Product and build
- LibreOffice 26.2.0 to 26.2.4
- Status
- Affected: the CVE record lists the 26.2 series before 26.2.5
- Source
- CVE.org record
- Product and build
- LibreOffice 25.8 and older
- Status
- Not listed in the CVE record. 25.8 has had no security updates since 12 Jun 2026
- Source
- CVE.org record; TDF 26.2.5 post
- Product and build
- Debian 13 trixie, 4:25.2.3-2+deb13u8
- Status
- Fixed by DSA-6543-1
- Source
- Debian security tracker
- Product and build
- Debian 12 bookworm, 4:7.4.7-1+deb12u13
- Status
- Marked vulnerable, no fix listed
- Source
- Debian security tracker
- Product and build
- Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS
- Status
- Needs evaluation, priority Medium
- Source
- Ubuntu CVE page
- Product and build
- SUSE Linux Enterprise 15 SP7
- Status
- libreoffice listed as Affected
- Source
- SUSE CVE page
- Product and build
- Apache OpenOffice 4.1.16 and earlier
- Status
- Affected, no fix released. 4.1.17-RC1 vote open
- Source
- Apache bulletin; development list
| Product and build | Status | Source |
|---|---|---|
| LibreOffice 26.8.0 and later (26.8.1 was announced on 2 Oct but delayed by mirror problems) | Fixed | TDF advisory; TDF release posts |
| LibreOffice 26.2.5 and later (26.2.6 on 4 Sep) | Fixed | TDF advisory; TDF release posts |
| LibreOffice 26.2.0 to 26.2.4 | Affected: the CVE record lists the 26.2 series before 26.2.5 | CVE.org record |
| LibreOffice 25.8 and older | Not listed in the CVE record. 25.8 has had no security updates since 12 Jun 2026 | CVE.org record; TDF 26.2.5 post |
| Debian 13 trixie, 4:25.2.3-2+deb13u8 | Fixed by DSA-6543-1 | Debian security tracker |
| Debian 12 bookworm, 4:7.4.7-1+deb12u13 | Marked vulnerable, no fix listed | Debian security tracker |
| Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS | Needs evaluation, priority Medium | Ubuntu CVE page |
| SUSE Linux Enterprise 15 SP7 | libreoffice listed as Affected | SUSE CVE page |
| Apache OpenOffice 4.1.16 and earlier | Affected, no fix released. 4.1.17-RC1 vote open | Apache bulletin; development list |
What to do, in the order worth doing
Take this with you
Actions, most useful first
- Inventory every copy of LibreOffice and Apache OpenOffice with its version: installed, per-user, portable and USB copies, distribution packages, and any server that runs an office program to convert or preview uploaded files. Note which machines also have a Java runtime.
- LibreOffice: update to 26.2.5 or later on the 26.2 branch, or 26.8.0 or later. At 14:50 BST on 6 October TDF's download page offered 26.8.0 and 26.2.6. The 26.2 branch is supported until 30 November 2026, and 25.8 and older are out of support.
- Apache OpenOffice 4.1.16 and earlier: untick Use a Java runtime environment (Tools, Options, OpenOffice, Java; on macOS, OpenOffice, Preferences, OpenOffice, Java), or remove the Java runtime from machines that do not need Base or the wizards. Install 4.1.17 when it is released, after reading its bulletin.
- Until OpenOffice is fixed, treat spreadsheets from outside the organisation as untrusted in OpenOffice: open them in a patched LibreOffice, another viewer or a sandbox, or not at all. Decide whether OpenOffice should stay on the estate.
- Linux: read your distribution's tracker today and do not assume the packaged version matches TDF's numbering. On 6 October Debian listed trixie as fixed and bookworm as vulnerable, Ubuntu listed four LTS releases as needs evaluation, and SUSE listed SLE 15 SP7 as affected.
- Where policy allows, stop office programs fetching from the internet directly, with a host firewall rule per program or a proxy that logs and denies by default. Both advisories describe code loaded from a remote location, so this should break the route even on an unpatched build. It is a defensive suggestion and not something either project documents.
- Mail and web gateways, a judgement: quarantine or detonate inbound ODS spreadsheets for now. The database file is described as fetched from a remote address, so blocking ODB attachments adds little. HMRC's own forms are ODS, so a blanket block will break real work.
- If you keep network logs, look for office processes making outbound connections to hosts you do not recognise at the moment a spreadsheet is opened, and for outside spreadsheets opened on affected builds since the proof of concept appeared on 5 October.
- Tell users not to open a spreadsheet they did not expect, in LibreOffice or OpenOffice, until the machine is updated. The absence of a prompt is not evidence of safety, which is the point of this flaw.
- Cyber Essentials: treat 19 October as the latest date for the 14-day count on LibreOffice, record why for any copy still older, and for OpenOffice record the Java mitigation and the date you will review it.
The question the 73 days leave
The facts are not in dispute. A fixed LibreOffice build existed for 73 days before anyone told its users why they needed it, and an OpenOffice candidate that appears to carry the fix is waiting on a vote, while a public proof of concept is about a day old. What decides who is exposed is not the advisory feed. It is whether an update process runs by default or waits for a reason. Cyber Essentials counts its 14 days from release, as the briefing on Debian's 1,313-CVE kernel update also found, and that assumes someone noticed the release.
If TDF had never published that advisory, which of your office suites would your update process have patched on 24 July, and which would still be waiting for a reason to move?
Sources
- PrimaryLibreOffice security advisories: CVE-2026-63277 and five other data-link advisories, announced 5 October 2026, fixed in 26.2.5 and 26.8.0; also the 26.2.5-only advisories of 21 SeptemberThe Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice security policy: disclosure within 30 days of resolutionThe Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.2.5 is available for download: post dated 24 July 2026, text datelined 23 July; 25.8 end of life 12 June 2026The Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.8 announcement, 26 August 2026The Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.8.1 announcement, 2 October 2026: release delayed by mirror problems; 26.2 supported until 30 November 2026The Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice release notes page: 26.8.0 dated 26 August 2026, 26.2.6 listed as the previous branchThe Document Foundationaccessed 2026-10-06
- PrimaryDownload server directory listing with file times for 26.2.5, 26.2.6, 26.8.0 and 26.8.1The Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.8 Help, Advanced options: the Java runtime settingThe Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.8 Help, Calc General options: update links when loadingThe Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice 26.8 Help, Data Provider for SpreadsheetsThe Document Foundationaccessed 2026-10-06
- PrimaryLibreOffice system requirements: Java needed for certain features, notably BaseThe Document Foundationaccessed 2026-10-06
- PrimaryTDF blog post of 6 October 2026: LibreOffice 26.8 over 4 million downloads in SeptemberThe Document Foundationaccessed 2026-10-06
- PrimaryCVE.org record for CVE-2026-63277: CNA The Document Foundation, CVSS 4.0 8.5, affected 26.2 series before 26.2.5, CISA SSVC entryCVE Programaccessed 2026-10-06
- PrimaryCVE.org record for CVE-2026-59265: CNA Apache, Critical, CISA-ADP CVSS 3.1 8.8 and SSVC entry, patch referencesCVE Programaccessed 2026-10-06
- PrimarySecurity bulletin for CVE-2026-59265: affected versions, Critical, Java mitigation, 4.1.17 in the release candidate phaseApache OpenOfficeaccessed 2026-10-06
- PrimaryApache OpenOffice security bulletin archive: five prompt-less remote-load issues fixed in 4.1.16Apache OpenOfficeaccessed 2026-10-06
- PrimaryApache announcement of CVE-2026-59265, 2 October 2026Apache Software Foundation via Openwall oss-securityaccessed 2026-10-06
- PrimaryDownloads page: current version 4.1.16, released 10 November 2025Apache OpenOfficeaccessed 2026-10-06
- PrimaryVote call for 4.1.17-RC1 as GA, 26 September 2026, open for 14 days, with replies to 4 OctoberApache OpenOffice development listaccessed 2026-10-06
- PrimaryJava and Apache OpenOffice: what needs Java, no JRE packaged since 3.4, the option to switch it offApache OpenOfficeaccessed 2026-10-06
- PrimaryDownload and install instructions: a JRE is no longer packagedApache OpenOfficeaccessed 2026-10-06
- PrimaryNVD record for CVE-2026-63277 via the API at 13:46 UTC on 6 October 2026: status Received, no NVD scoreNIST NVDaccessed 2026-10-06
- PrimaryNVD record for CVE-2026-59265 via the API at 13:46 UTC on 6 October 2026: status Deferred, no NVD scoreNIST NVDaccessed 2026-10-06
- PrimaryKnown Exploited Vulnerabilities catalogue version 2026.10.04, released 4 October 2026 at 18:52 UTC, 1,734 entriesCISAaccessed 2026-10-06
- PrimaryEPSS score for CVE-2026-59265, dated 5 October 2026FIRSTaccessed 2026-10-06
- PrimaryV12's post of 5 October 2026 announcing the flaw and describing its tool as an autonomous AI hackerV12accessed 2026-10-06
- PrimaryV12 blog index at 14:42 BST on 6 October 2026: no write-up of this flaw; company statements on fundingV12accessed 2026-10-06
- PrimaryCodean Labs blog index at 14:42 BST on 6 October 2026: no write-up of this flawCodean Labsaccessed 2026-10-06
- PrimaryDebian tracker entry for CVE-2026-63277: trixie fixed, bookworm vulnerable, DSA-6543-1Debian Security Trackeraccessed 2026-10-06
- PrimaryUbuntu CVE page for CVE-2026-63277: needs evaluation on four LTS releases, priority MediumCanonicalaccessed 2026-10-06
- PrimarySUSE CVE page for CVE-2026-63277: rated important, CVSS 3.1 7.8, SLE 15 SP7 affectedSUSEaccessed 2026-10-06
- PrimaryRed Hat CVE page for CVE-2026-63277: preliminary CVSS 3.1 7.8, mitigation textRed Hataccessed 2026-10-06
- PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026, Security Update ManagementNCSCaccessed 2026-10-06
- PrimaryVulnerability management: update by default, best-practice timescales, silent updatesNCSCaccessed 2026-10-06
- PrimaryMacro security for Microsoft Office: do not rely on click-through promptsNCSCaccessed 2026-10-06
- PrimaryUsing Open Document Formats in your organisation: ODF 1.2 selected for government, LibreOffice listedGOV.UK, Government Digital Serviceaccessed 2026-10-06
- PrimaryGift Aid schedule spreadsheet guidance: ODF format, open in Excel or LibreOfficeHM Revenue and Customsaccessed 2026-10-06
- Reported byNews coverage of 6 October 2026 used as a pointer to the primariesThe Hacker Newsaccessed 2026-10-06


