TL;DR
The Document Foundation has fixed six flaws in LibreOffice, led by CVE-2026-63277, a LibreOffice Calc vulnerability that runs attacker code when a user opens a spreadsheet. Researchers have now published the technical details and proof-of-concept exploit code. Users should upgrade to LibreOffice 26.2.5 or 26.8.0.
- Total: 6 CVEs
- Severity: 1 High · 5 Medium
- Actively exploited: None confirmed
- Highest severity: 8.5 (High · CVSSv4) — CVE-2026-63277
- Action: Apply the latest security updates now
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-63277 | 8.5 | RCE via calcext:data-mappings, sql provider and jdbc connector | < 26.2.5 | Not exploited |
| CVE-2026-63266 | 6.8 | Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality | < 26.2.5 | Not exploited |
| CVE-2026-63267 | 6.7 | LFI and GET SSRF via calcext:data-mappings and csv provider | < 26.2.5 | Not exploited |
| CVE-2026-63268 | 6.7 | LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href | < 26.2.5 | Not exploited |
| CVE-2026-63269 | 6.7 | LFI and GET SSRF via GStreamer and HLS playlists | < 26.2.5 | Not exploited |
| CVE-2026-63270 | 6.7 | Environment/ini-file leaks | < 26.2.5 | Not exploited |
Why It Matters
Opening a document is all it takes. No macro is involved, and no warning appears first. The V12 write-up states that LibreOffice runs the attacker’s code “without a macro-style safety warning or active-content prompt.”
The PoC is public in the V12 security GitHub repository. Because the details are out, attackers can study the technique quickly. Even so, CISA’s assessment in the CVE records lists exploitation as “none,” and no attacks in the wild have been confirmed.
How the Attacks Work
Code Execution (CVE-2026-63277)
Calc can link a cell range to an external data source, and the document saves that link. According to The Document Foundation, “a document could name a Java database driver for such a link to be loaded from a remote location.” Opening the file could then run Java code from that location. The flaw needs Java and JDBC support to be installed and enabled. Rick de Jager of V12 and Codean Labs researchers reported it.
File Write and File Read Bugs
The same data-link feature drives three more bugs. CVE-2026-63266 lets a document open an embedded Firebird database that “wrote a file to any location the user could write to.” Meanwhile, CVE-2026-63267 and CVE-2026-63268 can pull local files into the sheet. The first can also make requests to a host the document chooses.
Data Leaks
CVE-2026-63269 abuses linked media on Linux, where GStreamer could follow HLS playlists to local files and remote URLs. Finally, CVE-2026-63270 lets crafted links expand environment variables or INI file values. That data “could be exfiltrated to a remote server.” It closes gaps left by the earlier fix for CVE-2024-12426.
Affected Versions
All six flaws affect the LibreOffice 26.2 series before 26.2.5. The LibreOffice Calc vulnerability CVE-2026-63277 scores 8.5 on CVSS 4.0. The other five rate Medium, at 6.7 or 6.8.
Patch and Mitigation Steps
Upgrade to LibreOffice 26.2.5 or 26.8.0, as listed on the LibreOffice security advisories page. The fixes require Java class path entries to be local files and put external data links under normal link update control.
Until you patch, disable Java support in LibreOffice if you do not need it. That step blocks the most serious LibreOffice Calc vulnerability, since CVE-2026-63277 needs Java to run. Also treat spreadsheets from unknown senders with caution, and avoid opening them on systems that hold sensitive data.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!