OpenOffice patches two RCE vulnerabilities
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CERT-FR warns of multiple OpenOffice vulnerabilities before version 4.1.17 allowing remote code execution; update to patched release.
CERT-FR issued an advisory covering multiple vulnerabilities in Apache OpenOffice affecting versions prior to 4.1.17. The flaws, tracked as CVE-2026-59265 and CVE-2026-63277, could allow an attacker to achieve arbitrary remote code execution. No details on the exploitation vector or technical root cause are provided in the advisory beyond the risk classification.
No evidence of active exploitation in the wild is mentioned in this bulletin. Defenders should consult the OpenOffice security bulletin for patch details and update affected installations to version 4.1.17 or later as soon as possible to mitigate the risk of remote code execution.
Mentioned in this report
Detection guidance
Apache OpenOffice Spawning Shell or Script Interpreter
OpenOffice (soffice) launching a command shell, script host or LOLBin child process, a generic post-exploitation sign of RCE or malicious macro/document abuse. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Apache OpenOffice Spawning Shell or Script Interpreter
description: Detects Apache OpenOffice processes (soffice.exe/soffice.bin) spawning
command shells, script hosts or common download/execute LOLBins. The advisory gives
no exploit details, so this is a generic behavioural detection of code execution
from the office suite. It is not tied to any specific CVE artefact.
tags:
- attack.execution
- attack.t1203
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- \soffice.exe
- \soffice.bin
Image|endswith:
- \cmd.exe
- \powershell.exe
- \pwsh.exe
- \wscript.exe
- \cscript.exe
- \mshta.exe
- \rundll32.exe
- \regsvr32.exe
- \certutil.exe
- \bitsadmin.exe
condition: selection
falsepositives:
- Documents with legitimate macros that call cmd.exe or PowerShell for business automation
- Admin-deployed OpenOffice extensions that invoke helper scripts during install or
update
level: medium
id: e4a945b8-cc33-5f71-b6fd-eab91e840ec8
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1260
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1260
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,758 reports from 152 sources, 489 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs