Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-59265
CVE
CVE-2026-59265
View on NVD ↗
Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover
MITRE ATT&CK TTPs
3
T1105
Ingress Tool Transfer
Command And Control
T1202
Indirect Command Execution
Defense Evasion
T1203
Exploitation for Client Execution
Execution
Source Articles
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A vulnerability in LibreOffice and Apache OpenOffice allows malicious spreadsheets to execute arbitrary code without macro warnings by leveraging Java-based database drivers. The attack abuses legitimate features like database ranges and JDBC drivers, automatically downloading and executing a malicious JAR file when the document is opened. While LibreOffice has patched the issue (CVE-2026-63277), Apache OpenOffice remains vulnerable (CVE-2026-59265) in all versions up to 4.1.16. Users are advised to disable Java support or avoid untrusted spreadsheets until updates are available.
hacker-news
Oct 6, 2026