Hispasec•October 6, 2026•🇪🇸Translated from Spanish

LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings

Two vulnerabilities allow attackers to execute arbitrary code simply by opening manipulated office documents, bypassing the usual macro security warnings. The flaws affect LibreOffice Calc and Apache OpenOffice through their integration with Java and the way these applications resolve certain components when loading untrusted files.

CVE-2026-63277 impacts LibreOffice and permits a crafted spreadsheet to trigger loading of a Java database driver from a remote location. The root cause lies in class path handling: an attacker-controlled entry can point outside the local system, causing the application to fetch and execute classes from an external source. The fix enforces that every class path entry must be a file-type URL, effectively blocking remote class loading.

Users should update LibreOffice to version 26.2.5 or 26.8.0 or later. These releases also harden handling of external data links and JDBC connectors in Calc, reducing exposure in environments that regularly exchange spreadsheets containing database connections.

CVE-2026-59265 affects Apache OpenOffice 4.1.16 and earlier, enabling local or remote code execution when a malicious document abuses the Java integration. A stable patch is planned for 4.1.17, currently available only as a release candidate. Until then, administrators should disable Java support in OpenOffice wherever it is not strictly required.

Additional defensive steps include limiting Java usage across office suites on endpoints that frequently open attachments, enforcing strict policies against opening files from untrusted origins, and applying application isolation where feasible. Running office applications with the lowest possible privileges further contains any successful exploitation to the user’s permission boundary.

Related articles

BoletimSec•Vulnerabilities & Exploits

Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing

The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.

BoletimSec•Vulnerabilities & Exploits

Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access

Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.

Security NEXT•Vulnerabilities & Exploits

Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score

Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.