LibreOffice and OpenOffice Java Flaw Enables Silent Code Execution via Malicious Spreadsheets
Proof-of-concept attack bypasses macro warnings when Java support is enabled

Key Takeaways
- A proof-of-concept attack allows silent code execution in LibreOffice and Apache OpenOffice via malicious spreadsheets.
- The vulnerability requires Java support to be enabled within the affected office suites.
- No macro warnings are triggered before code execution occurs.
- No confirmed in-the-wild exploitation has been reported as of October 2026.
Related Security News

SonicWall Issues Hotfixes for Maximum-Severity SSRF Flaw in SMA1000 Gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) vulnerability affecting SMA1000 series appliances. The flaw could allow attackers to force the appliance to make unintended requests, potentially leading to unauthorized access, data exfiltration, or lateral movement within affected networks. Users are advised to apply the latest firmware updates immediately.

Critical Vulnerabilities Discovered in Anthropic's Model Context Protocol Implementation
Researchers from OX Security identified critical vulnerabilities in the implementation of Anthropic's Model Context Protocol across 15,465 publicly exposed servers. The findings include insecure authentication mechanisms, absence of rate limiting, and improper credential storage. These flaws could allow unauthorized access to AI models and data, credential theft, and manipulation of agent workflows. The report was published on October 6, 2026, and highlights the need for immediate security reviews of MCP deployments.



