MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via The Hacker News

Critical Vulnerability in LibreOffice and OpenOffice Allows Silent Code Execution via Spreadsheets

Image via The Hacker News
Image via The Hacker News

Security researchers have identified vulnerabilities in LibreOffice and Apache OpenOffice that enable malicious spreadsheets to execute arbitrary code upon opening without triggering macro security warnings. The exploit requires Java support to be enabled within the office applications and has currently only been demonstrated as a proof-of-concept with no confirmed real-world attacks. This vulnerability poses a significant risk to users who open untrusted spreadsheet files, as the attack bypasses the standard security mechanisms users rely on.

Expanded Detail

LibreOffice and Apache OpenOffice, widely-used open-source alternatives to commercial office software, contain security flaws that permit the execution of unauthorized programs through spreadsheet files. The vulnerability operates by circumventing the protective warnings that normally alert users when macros or executable content attempt to run, creating a silent attack vector.

The flaw depends on Java functionality being active within these applications. While researchers have demonstrated the concept's feasibility, there is currently no evidence of attackers exploiting this weakness in actual incidents. Users who handle spreadsheets from unknown or untrusted sources face the greatest exposure.

Context

This vulnerability could affect millions of users relying on LibreOffice and OpenOffice across enterprises, educational institutions, and individual users. Organizations may need to review their security policies regarding spreadsheet handling and Java integration in office software. The incident highlights how even open-source applications require vigilant security monitoring, and may prompt users to reconsider which applications they trust with untrusted documents or to adjust their Java settings as a precautionary measure.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Critical Vulnerabilities Discovered in Armatura One Access Control Systems · Cybersecurity
New ClickFix Variant Exploits Browser Cache to Deliver Malicious Code Undetected · Cybersecurity
Fortinet Issues Critical Patch for FortiMail Flaw Allowing Unauthorized File Creation · Cybersecurity
Critical vulnerability in Dell's update tool allows remote root access on servers · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings.” Browse more stories.