# OpenOffice patches two RCE vulnerabilities

Published: 2026-10-05 · Severity: routine
Canonical: https://vorant.io/reports/12128738-19fa-58d6-a029-dc9081116c2c/openoffice-patches-two-rce-vulnerabilities

> CERT-FR warns of multiple OpenOffice vulnerabilities before version 4.1.17 allowing remote code execution; update to patched release.

CERT-FR issued an advisory covering multiple vulnerabilities in Apache OpenOffice affecting versions prior to 4.1.17. The flaws, tracked as CVE-2026-59265 and CVE-2026-63277, could allow an attacker to achieve arbitrary remote code execution. No details on the exploitation vector or technical root cause are provided in the advisory beyond the risk classification.

No evidence of active exploitation in the wild is mentioned in this bulletin. Defenders should consult the OpenOffice security bulletin for patch details and update affected installations to version 4.1.17 or later as soon as possible to mitigate the risk of remote code execution.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59265, CVE-2026-63277

## Detection guidance (public sample)

### Apache OpenOffice Spawning Shell or Script Interpreter

ATT&CK: T1203

OpenOffice (soffice) launching a command shell, script host or LOLBin child process, a generic post-exploitation sign of RCE or malicious macro/document abuse. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Apache OpenOffice Spawning Shell or Script Interpreter
description: Detects Apache OpenOffice processes (soffice.exe/soffice.bin) spawning
  command shells, script hosts or common download/execute LOLBins. The advisory gives
  no exploit details, so this is a generic behavioural detection of code execution
  from the office suite. It is not tied to any specific CVE artefact.
tags:
- attack.execution
- attack.t1203
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith:
    - \soffice.exe
    - \soffice.bin
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \regsvr32.exe
    - \certutil.exe
    - \bitsadmin.exe
  condition: selection
falsepositives:
- Documents with legitimate macros that call cmd.exe or PowerShell for business automation
- Admin-deployed OpenOffice extensions that invoke helper scripts during install or
  update
level: medium
id: e4a945b8-cc33-5f71-b6fd-eab91e840ec8
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1260
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1260

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/12128738-19fa-58d6-a029-dc9081116c2c/openoffice-patches-two-rce-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
