LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

Executive Summary

Security researchers demonstrated that a malicious spreadsheet can execute attacker code immediately upon opening in LibreOffice and Apache OpenOffice when Java support is enabled, bypassing macro warnings. The proof‑of‑concept attack shows no real‑world reports yet.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-06T11:57:00+00:00 - Category: threat-intel

Original Description: A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in

"Through pride we are ever deceiving ourselves. But deep down below the surface of the average conscience a still, small voice says to us, Something is out of tune."

— Carl Jung
Source: The Hacker News