AntiMalware•October 7, 2026•🇷🇺Translated from Russian

LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings

Security researchers have uncovered a vulnerability in LibreOffice and Apache OpenOffice that allows attackers to execute arbitrary code simply by tricking users into opening a malicious spreadsheet file.

The attack does not rely on macros and therefore bypasses the usual security warnings that appear when macros are present. The only prerequisite is that Java support must be enabled inside the office suite.

The flaw stems from the interaction between two legitimate features. LibreOffice Calc can automatically refresh cell ranges from an external database source. When a specially crafted document is opened, the application loads the referenced database file, which in turn points to a Java driver supplied by the attacker. This driver executes inside the office process, granting the attacker full code execution capabilities.

LibreOffice addressed the issue, tracked as CVE-2026-63277, by releasing versions 26.2.5 and 26.8.0 on 5 October. Users are strongly encouraged to update immediately.

Apache OpenOffice is affected by a similar vulnerability, CVE-2026-59265, in all versions up to and including 4.1.16. A patch is planned for version 4.1.17, which is still undergoing testing. Until the update is released, OpenOffice users should either disable Java in the application settings or refrain from opening untrusted spreadsheet files.

The researchers demonstrated the attack by launching the system calculator, confirming remote code execution. The same method can be used to run any Java payload. The issue was confirmed on both Windows and Linux. No evidence of active exploitation in the wild has been observed yet.

Related articles

Hispasec•Vulnerabilities & Exploits

Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release

Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.

BoletimSec•Vulnerabilities & Exploits

Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence

Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.

BoletimSec•Vulnerabilities & Exploits

Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper

Apache Struts has patched four vulnerabilities, one of which permits unauthenticated remote code execution through an OGNL injection flaw. The issue, tracked as CVE-2026-104711, only affects applications that still rely on the legacy RESTful mapper; modern configurations using the default mapper, restful2, or the official Struts REST plugin remain unaffected. Exploitation occurs when the legacy mapper extracts action names and parameters directly from the URL, allowing attackers to inject malicious OGNL expressions. Vulnerable releases span 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, and 7.0.0–7.3.0, with fixes available in 6.12.0 and 7.4.0. The remaining three flaws impact availability or cause cross-request data leakage but do not lead to code execution, and only one received an “important” severity rating.

Habr•Vulnerabilities & Exploits

Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery

The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.