LibreOffice CVE-2026-63277: Patch This Office Flaw
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
18926
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-18926,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

A Spreadsheet That Runs Code the Moment You Open It: The LibreOffice and OpenOffice Flaws Dental Offices Should Patch Now

A spreadsheet document quietly releasing a thread of malicious code into a computer, with no warning dialog shown

A Spreadsheet That Runs Code the Moment You Open It: The LibreOffice and OpenOffice Flaws Dental Offices Should Patch Now

Most dental teams have been trained to fear one thing when a document lands in their inbox: the macro warning. Open an attachment, see the yellow bar asking whether to enable macros, and you know to stop and think. A disclosure published on October 6, 2026 by The Hacker News describes something more unsettling — a booby-trapped spreadsheet that makes LibreOffice or Apache OpenOffice run an attacker’s code the instant the file is opened, with no macro warning at all. The safeguard your staff rely on never appears.

If your practice uses either of these free office suites — and a great many do, on reception machines and back-office PCs, precisely because they are free — this is worth ten minutes of attention today.

A spreadsheet document quietly releasing a thread of malicious code into a computer, with no warning dialog shown
The danger of this flaw is what is missing: the file runs code on open, with none of the warnings users are trained to expect.

What researchers actually found

Security researchers demonstrated that a specially crafted spreadsheet can achieve remote code execution: opening the file is enough to run commands of the attacker’s choosing on the computer, at the privilege level of whoever opened it. There is no “enable content” prompt, no macro bar, no second chance to say no. The flaw is tracked as CVE-2026-63277 in LibreOffice and as the matching CVE-2026-59265 in Apache OpenOffice.

One important qualifier: as reported, the attack has only been shown as a proof of concept, and there are no reports yet of it being used in real-world attacks. That is the good news — and the reason to patch now, before a working exploit circulates, rather than after.

Why there is no warning — the clever part

What makes this flaw instructive is that it does not rely on a single broken feature. It chains together capabilities that each work exactly as designed. A Calc spreadsheet can contain a database range: a block of cells that pulls in data from an outside source and refreshes itself automatically. That external source can be made to deliver far more than numbers. Combined with the program’s Java support, the refreshing data range can be steered into executing code rather than simply importing it.

Because each ingredient is a legitimate feature, none of them trips the macro-security prompt. The attack lives in the gap between two trusted behaviours — which is exactly the kind of blind spot that bypasses user training. A critical detail for mitigation: the attack only works when the program’s Java support is enabled.

Two spreadsheets compared: one shows a macro warning, the other has the warning removed
A macro prompt (left) gives the user a choice. This attack (right) removes that choice.

What is fixed and what is not

The two projects are in very different places, and this is the part practice owners need to get right:

  • LibreOffice has already fixed it. The patch shipped in updates released on October 5, 2026. LibreOffice recommends moving to version 26.2.5 or 26.8.0; every version before those is affected.
  • Apache OpenOffice has not fixed it yet. Every version up to and including the current release, 4.1.16, is affected. The project says a fix is expected in version 4.1.17, which is still being tested. Until that arrives, OpenOffice users are exposed unless they take a manual step.
A spreadsheet pulling data from an external source through a Java runtime, illustrating how the attack chains together
The attack abuses ordinary features — a self-refreshing external data range plus Java — that each behave as designed on their own.

Why this matters more in a dental office than you might think

A dental practice is a near-perfect target for a document-borne attack, for reasons that have nothing to do with how careful your team is. The front desk opens unfamiliar attachments all day: insurance remittances, patient intake forms, supplier invoices, referral letters from other offices. A malicious spreadsheet does not need to look exotic — it needs to look like a Tuesday.

And the machine that opens it is rarely isolated. On a typical practice network it can see the practice-management database, the imaging share, and whatever cloud sessions are logged in. Code running as the front-desk user is code running with the front desk’s reach into patient data — which, under PHIPA and HIPAA, turns a “someone opened a bad file” moment into a potential reportable breach. The same uncomfortable logic applies to any workstation flaw that executes with the user’s own permissions, which is why we treat seemingly minor desktop CVEs as practice-wide events, not just one person’s problem.

What to do this week

None of the fixes here are difficult. They just have to actually happen on every machine, not only the one you remember.

  • Inventory first. Find every computer in the practice running LibreOffice or Apache OpenOffice — including the quiet back-office PC nobody logs into much. You cannot patch what you have forgotten about.
  • Update LibreOffice now to 26.2.5 or 26.8.0. If your office is on a much older release, this is also a good moment to get current rather than inch forward.
  • On Apache OpenOffice, disable Java until 4.1.17 ships. Because the attack requires Java support, turning it off in the program’s settings blocks this flaw outright. Most practices never use OpenOffice’s Java features anyway. When 4.1.17 is released, update to it.
  • Reinforce the oldest rule: do not open spreadsheets you do not trust. A referral or invoice you were not expecting deserves a phone call to confirm before it is opened, especially while OpenOffice remains unpatched.
  • Consider consolidating. If free office suites are scattered across the practice without anyone tracking versions, that sprawl is the real vulnerability. Knowing what software runs where, and keeping it current, is the whole game.
A front-desk computer opening an emailed spreadsheet attachment near icons representing patient records at risk
In a practice, the opening move is almost always an emailed attachment — an invoice, a form, a referral — landing at the front desk.

The pattern behind the headline

It is tempting to file this under “another CVE” and move on. The more useful takeaway is the mechanism: attackers increasingly string together ordinary, approved features to slip past the warnings users are trained to heed. You cannot train your way out of a threat that shows no prompt. What protects a practice is the unglamorous discipline underneath — knowing every piece of software on every machine, keeping it patched, and removing features (like unused Java support) that only widen the attack surface.

A settings panel turning Java off and an update arrow installing a patched office suite version
Two clean fixes: install the patched version, and — especially on OpenOffice — turn off Java support until a fix ships.

How Compudent Systems can help

At Compudent Systems, we manage the desktops and networks behind dental practices across the GTA and Ontario, which means keeping an inventory of what runs where and patching flaws like CVE-2026-63277 before they become incidents. We can audit your practice for vulnerable LibreOffice and OpenOffice installs, apply the fixes, disable unnecessary high-risk features, and put a patch-management routine in place so the next document-borne flaw is handled quietly in the background. Contact Compudent Systems for a security assessment and proactive patch management — and turn “someone opened a bad file” from a crisis into a non-event.


Sources & further reading:

Related Reading



Contact us today - How can we help you?