LibreOffice Fixes Critical RCE Bug and 5 Other Flaws — Patch Now
The Document Foundation patched six LibreOffice vulnerabilities, including a remote-code-execution flaw triggered by simply opening a document; update to 26.2.5 or 26.8.0 now.

The Document Foundation disclosed six LibreOffice vulnerabilities on October 5, 2026, and the worst of them lets an attacker run arbitrary code on a victim's machine the moment they open a booby-trapped spreadsheet. All six are fixed in LibreOffice 26.2.5 and 26.8.0, and anyone running an older build on Windows, macOS, or Linux should update now.
LibreOffice is the default office suite on a large share of Linux desktops and is widely deployed by schools, government agencies, and businesses that standardized on it as a free alternative to Microsoft Office. All six issues disclosed this week trace back to the same general area of the code: the external data-link features in LibreOffice Calc, which let a spreadsheet pull in live data from a database, a CSV file, or a network location. Those features are powerful, and the advisories make clear they were also under-protected against a document that abuses them.
What happened: The Document Foundation published advisories for six LibreOffice CVEs on October 5, 2026.
Worst case: CVE-2026-63277 — remote code execution just from opening a Calc spreadsheet, CVSS 4.0 score 8.5 (High).
Fixed in: LibreOffice 26.2.5 and 26.8.0.
Exploited in the wild: No confirmed active exploitation as of this writing, per NVD's vulnerability-response data.
What to do: Update via Help > Check for Updates, or download the current installer from libreoffice.org.
The critical flaw: a spreadsheet link that runs Java code
The headline issue is CVE-2026-63277, a remote-code-execution bug in LibreOffice Calc. Calc lets a cell range link to an external data source, and that link — including its configuration — is saved inside the document itself. According to The Document Foundation's advisory, a malicious document can point one of those links at a Java database (JDBC) driver hosted on a remote server. When the victim opens the file, LibreOffice fetches that driver from the attacker's location and executes its Java code automatically, no further clicks required.
That makes it a true "just open the file" bug: no macros to enable, no dialog to click through, no plugin to approve. NVD scores it 8.5 on the CVSS 4.0 scale (High severity), with a vector showing a local attack surface, low complexity, no privileges needed, and only passive user interaction — i.e., simply opening the document. The fix requires that any Java class-path entry used in such a link be a local file URL, closing off the remote-loading path entirely.
The flaw was reported independently by two parties: Rick de Jager of the V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs. Caolán McNamara of Collabora Productivity, LibreOffice's most prolific security fixer, wrote the patch.
The weakness is conceptually similar to attacks security researchers have long warned about in Microsoft Office documents that trigger unwanted network or code-execution behavior on open, such as DDE-based payloads or remotely loaded templates. The common thread is that modern office documents aren't just static files; they're small programs that can reach out to the network and the local filesystem by design, and attackers look for the gap between what a feature is supposed to fetch and what it will actually accept.
Five more flaws patched in the same release
The other five advisories published the same day share a common root cause with the critical bug: LibreOffice Calc's external-data-link feature, which is more exposed than most users realize. None reach the severity of CVE-2026-63277, but several still allow an attacker to steal local files or make the victim's machine quietly contact a remote server, just by getting them to open a document.
| CVE ID | Issue | CVSS 4.0 | Fixed in |
|---|---|---|---|
| CVE-2026-63277 | Remote code execution via a malicious JDBC driver link | 8.5 — High | 26.2.5 / 26.8.0 |
| CVE-2026-63266 | Arbitrary file write via an embedded Firebird database | 6.8 — Medium | 26.2.5 / 26.8.0 |
| CVE-2026-63267 | Local file read and SSRF via a CSV data link | 6.7 — Medium | 26.2.5 / 26.8.0 |
| CVE-2026-63268 | Local file read via a SQL data link to a folder of text files | 6.7 — Medium | 26.2.5 / 26.8.0 |
| CVE-2026-63269 | Local file read and SSRF via GStreamer HLS playlists | 6.7 — Medium | 26.2.5 / 26.8.0 |
| CVE-2026-63270 | Environment-variable and INI-file value leaks via crafted URLs | 6.7 — Medium | 26.2.5 / 26.8.0 |
CVE-2026-63266 affects documents that embed a Firebird database (LibreOffice's built-in database engine for Base files). A crafted link could trigger the embedded database's backup function to write a file to any location the user's own account could write to — a classic arbitrary-file-write bug. The fix now sandboxes an embedded Firebird database to its own private directory.
CVE-2026-63267 and CVE-2026-63268 both abuse Calc's CSV and SQL external-data providers. In the first, a link was fetched automatically while the document loaded, letting a malicious file silently pull a local file into the sheet or make the victim's machine send a request to a server of the attacker's choosing (a GET-based server-side request forgery). In the second, a SQL-type link could name an entire folder of local text files as if it were a database, reading their contents into the spreadsheet. The Document Foundation closed the first by putting external links under the same update-control prompt as ordinary document links, and the second by restoring only the CSV, HTML, and XML providers automatically on load.
CVE-2026-63269 is the odd one out: it runs through GStreamer, the media framework LibreOffice uses on Linux to play linked audio and video. A linked media file could be an HLS playlist that instructed GStreamer to read further local files and remote URLs listed inside it while the document opened, with their contents potentially surfacing in the document. LibreOffice no longer follows playlists that reference other resources, and linked media is now covered by the same link-update control as other link types.
CVE-2026-63270 is a leak, not a direct compromise: a document could construct a URL that expanded an environment variable or a value from an INI configuration file, exfiltrating that value to a remote server when the document opened. The Document Foundation had partly closed this class of bug before, for a related 2024 issue, but that earlier check didn't cover every place a document could supply a URL — specifically XForms instance data and the Calc CSV and SQL providers. Fixed versions now refuse document-supplied URLs that use internal schemes in those three spots.
Which versions are affected
LibreOffice ships two parallel release branches: a feature branch that gets a new version roughly every six months, and the previous feature branch, which keeps receiving bug and security fixes for a while after a new one replaces it. Right now that's 26.8, released in August 2026, and 26.2, the branch it replaced. NVD's records for CVE-2026-63277 and its five siblings list the affected range as the 26.2 series before 26.2.5 — the vulnerable code existed in that branch's released builds. The 26.8 branch's first stable release, 26.8.0, already shipped with the fix built in, which is why The Document Foundation lists both 26.2.5 and 26.8.0 as the fixed versions rather than a 26.8.x point release.
In practice, that means anyone on 26.2.0 through 26.2.4 was exposed, and anyone who adopted 26.8.0 at release was never vulnerable to begin with. Users still on older, no-longer-supported branches such as 25.8 or earlier won't receive a patch for these specific CVEs at all, because The Document Foundation only backports security fixes to the current and immediately prior feature branch; the only way to get the fix on an unsupported branch is to upgrade to a supported one.
Is LibreOffice being exploited right now?
No — not as far as any public record shows. NVD's vulnerability-response data for CVE-2026-63277 and its five siblings each list exploitation status as "none" confirmed, and The Document Foundation's advisories don't describe any of the six as having been found in an active attack. All six were reported responsibly by independent security researchers rather than discovered after an incident, which is the pattern security teams generally prefer: the people who found the bugs disclosed them privately to The Document Foundation, gave the project time to ship a fix, and only then went public, alongside the official advisory rather than ahead of it.
Pandromeda has not found, and The Document Foundation has not published, any report of these specific CVEs being used against real targets before the patch shipped. Readers should treat any claim otherwise with skepticism unless it points to a named, verifiable incident.
That's a meaningfully different situation from some of the other patch-now stories this desk has covered recently. Pandromeda's report on the FortiMail zero-day involved a flaw attackers were already using before Fortinet shipped a fix. This LibreOffice batch is the opposite scenario: six bugs caught and patched before anyone (publicly) weaponized them. That's good news, but it's not a reason to wait. A CVSS 8.5 remote-code-execution bug with a detailed public advisory is exactly the kind of flaw that gets reverse-engineered into a working exploit within days of disclosure, the way security teams have watched play out with other recent patch-now disclosures, including the back-to-back helpdesk flaws Pandromeda covered in Zammad's zero-days.
Who found and fixed the bugs
Credit for the critical flaw is shared between Rick de Jager of the V12 security team and the pair of Thomas Rinsma and Edoardo Geraci at Codean Labs, who reported it independently of each other — a sign the bug class was discoverable by more than one research group looking at the same code path. The Document Foundation's advisories credit the same Codean Labs researchers, Rinsma and Geraci, with finding all five of the other issues as well. Caolán McNamara of Collabora Productivity, who has fixed the large majority of LibreOffice's disclosed security bugs over the past several release cycles, wrote the patches for all six.
How to update LibreOffice
Check your installed version first: open any LibreOffice application and go to Help > About LibreOffice. If it reads anything in the 26.2 series below 26.2.5, or 26.8 below 26.8.0, you're exposed.
- Inside LibreOffice, go to Help > Check for Updates and install the update if one is offered.
- Or download the current installer directly from the official LibreOffice download page for Windows, macOS, or Linux.
- If you installed LibreOffice through a Linux distribution's package manager, update through your distro's normal package channel; distro maintainers typically backport these fixes into their own package versions on their own schedule, which can lag the upstream release by days or weeks, so check your distribution's own advisory tracker if you can't move to 26.2.5 or 26.8.0 directly.
- In managed IT environments, LibreOffice's Windows build is also distributed as an MSI package suited to fleet deployment tools; IT administrators should push the update fleet-wide rather than relying on individual users to click through the in-app updater.
- Until you can update, treat spreadsheets and other documents from unfamiliar senders with extra caution — several of these bugs, including the critical one, require nothing more than opening the file. Disabling automatic update of external links (Tools > Options > LibreOffice Calc > General, in older interface layouts) reduces exposure to the five lower-severity flaws, though it does not substitute for installing the fix.
What's next
With the fixes now public, the technical detail in The Document Foundation's own advisories is enough for a capable attacker to work backward toward a proof-of-concept, which is the usual pattern after an open-source project discloses a patched vulnerability. Expect security researchers and red teams to publish technical write-ups and possibly working exploits for CVE-2026-63277 in the coming weeks, which is roughly the pattern seen after past disclosures covered on this desk, including the critical Atlassian file-read flaw from earlier this year. Organizations that manage LibreOffice deployments centrally should treat this release the way they'd treat any office-suite RCE patch and push it through normal update channels on an accelerated timeline rather than waiting for a routine patch cycle. The Document Foundation maintains a public advisories page listing every past and future disclosure, which is the most reliable place to check before opening unfamiliar documents in bulk, and the NVD entry for CVE-2026-63277 is worth bookmarking if your organization tracks CVSS scores for patch prioritization.
Frequently asked questions
What is CVE-2026-63277?
It's a LibreOffice Calc vulnerability that lets a malicious spreadsheet point an external data link at a remote Java database driver. Opening the document causes LibreOffice to load and run that driver's Java code automatically, which The Document Foundation and NVD rate 8.5 (High) on the CVSS 4.0 scale. It's fixed in LibreOffice 26.2.5 and 26.8.0.
Do I need to open a macro or enable anything for these bugs to trigger?
No. All six flaws, including the critical one, are triggered just by opening a crafted document in Calc, with no macro approval, security-warning dialog, or plugin install required.
Which LibreOffice versions are vulnerable?
Builds in the 26.2 series before 26.2.5 are affected. LibreOffice 26.8.0, the first stable release of the newer 26.8 branch, shipped with the fix already included. Older, unsupported branches such as 25.8 won't receive a dedicated patch; upgrading to a supported branch is the only fix.
Has any of these six vulnerabilities been exploited in the wild?
Not as far as any public record shows. NVD's vulnerability-response data lists exploitation as unconfirmed for all six, and they were reported through responsible disclosure rather than discovered in an active attack.
How do I check what version of LibreOffice I'm running?
Open any LibreOffice application and go to Help > About LibreOffice. If the version shown is in the 26.2 series below 26.2.5, update immediately; 26.8.0 and later are already fixed.
Who reported and fixed these vulnerabilities?
Rick de Jager of the V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs, reported the critical flaw independently of each other; Codean Labs also reported the other five. Caolán McNamara of Collabora Productivity wrote the fixes for all six.
Sources
- The Document Foundation — LibreOffice Security Advisorieslibreoffice.org
- The Document Foundation — CVE-2026-63277 Advisorylibreoffice.org
- NVD — CVE-2026-63277 Detailnvd.nist.gov
- The Document Foundation — CVE-2024-12426 Advisorylibreoffice.org
- LibreOffice Download Pagelibreoffice.org
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


