Is LibreOffice Safe in 2026? OpenOffice Flaws and Updates

10 sources
Comments (0)

LibreOffice and OpenOffice security in 2026: the short answer

LibreOffice is safe to use in 2026 if you keep it updated. Its developers still publish security fixes often. On October 5, 2026 they announced six new flaws, including one that allowed remote code execution, all fixed in LibreOffice 26.2.5 and 26.8.0.[9]

Apache OpenOffice also still ships fixes, but less often. Its security bulletin lists version 4.1.16 as the release that fixes seven flaws numbered CVE-2025-64401 to CVE-2025-64407.[10] The signature spoofing bugs from our 2021 report below were fixed long ago, in OpenOffice 4.1.11 and the LibreOffice versions listed there.[3][4]

LibreOffice and OpenOffice security at a glance
QuestionLibreOfficeApache OpenOffice
Still getting security fixes?Yes, advisories announced in September and October 2026[9]Yes, the latest bulletin covers 4.1.16[10]
Version to run26.2.5 or 26.8.0 or newer[9]4.1.16 or newer[10]
Most serious recent flawRemote code execution via Calc data mappings and a JDBC connector[9]Remote documents loaded without a prompt[10]
2021 signature flawsFixed, see CVE-2021-25635[4]Fixed in 4.1.11[3]
Official downloadlibreoffice.org[6]openoffice.org[5]

Timeline: office suite flaws from 2021 to 2026

Timeline of LibreOffice and OpenOffice security fixes from the 2021 signature spoofing flaws to the October 2026 LibreOffice advisories
LibreOffice and OpenOffice security fixes, 2021 to 2026. Sources: Apache, LibreOffice.
Dated security events for both suites
DateEvent
October 2021Signature spoofing flaws reported and fixed, covered in our original report[1][3]
CVE-2025 seriesOpenOffice 4.1.16 fixes CVE-2025-64401 to CVE-2025-64407[10]
September 21, 2026LibreOffice announces heap buffer overflows in WMF and PDF import, fixed in 26.2.5[9]
October 5, 2026LibreOffice announces six flaws, including remote code execution, fixed in 26.2.5 and 26.8.0[9]

What changed since 2021

In 2021 the main worry was forged digital signatures that could make a macro look trusted.[2] The 2026 advisories show a different kind of risk. Several LibreOffice bugs abuse data mapping features in Calc to read local files, reach internal web addresses or, in one case, run code.[9] Others are heap buffer overflows in the import of WMF images and PDF files.[9]

OpenOffice's recent fixes follow a similar theme. Five of the seven flaws in its latest bulletin let a document load remote content without asking the user, through IFrames, OLE objects, external data sources, images or the DDE function.[10] Another lets URL fetching leak settings and environment variables.[10] Opening a file can quietly contact a server the attacker controls.

One thing has not changed. LibreOffice versions now use a year-based number such as 26.2.5, so the old advice to run 7.0.5 or 7.1.1 in the text below is long out of date. Run the newest version the official site offers.[6][9]

Risks and scams around office suites (our analysis)

This list is our analysis of the common ways people get hurt through free office suites. It is not a quote from the vendors.

  • Fake download sites. Free and popular software is often copied onto look-alike sites that bundle adware or malware. Download only from libreoffice.org or openoffice.org.[5][6]
  • Macro documents in email. A file that asks you to enable macros is still the classic infection route described in our original report.[7]
  • Booby-trapped spreadsheets. The 2026 Calc flaws mean a crafted file could read local files or run code on an old version.[9]
  • Old installs that never update. Neither suite updates silently by default on every system, so old versions stay in use for years.

How to keep LibreOffice and OpenOffice safe

Six steps to keep LibreOffice and OpenOffice safe in 2026: check the version, update from the official site, keep macros off, distrust email files, turn on update checks, scan suspicious files
Six steps to keep LibreOffice and OpenOffice safe. 2-Spyware, 2026.

1. Check your version. Open the About window of the program to see which version you run. Compare it with the fixed versions listed in the vendor advisories.[9][10]

2. Update officially. Download LibreOffice from libreoffice.org and OpenOffice from openoffice.org.[5][6] Avoid download portals that wrap the installer in their own setup program.

3. Keep macros off. Open the macro security setting in the program options and choose a high level, so that unsigned macros do not run. The vendors' help pages show the exact menu for your version. Enable macros only for a file you created or fully trust.

4. Distrust email files. Invoices, orders and "confidential" files from unknown senders are typical lures, as our original report explains.[7]

5. Turn on checks. Keep the built-in update check enabled rather than disabling it. Disabling updates leaves known flaws open.

6. Scan odd files. If a file behaves strangely or you already enabled macros, scan the computer. Our virus removal guides explain what to look for.

What is still unknown

  • Whether any of the 2026 LibreOffice flaws were exploited before the fix. The advisories we read do not say so.[9]
  • The exact release date of OpenOffice 4.1.16 and whether a newer release is planned. The bulletin we read lists the fixes but we did not confirm a date.[10]
  • How many users still run versions older than the fixes. We found no public figure.

We will update this page when either project publishes a new security advisory that changes this advice.

Our original 2021 report

The text below is our report as first published in 2021. We keep it unchanged for the record; the sections above bring it up to date.

Productivity software flaws might get used by malicious actors, so the security update is shipped by maintainers.[1] The flaw can provide the ability to manipulate documents into appearing to be digitally signed by the trusted source.[2] These digital signatures are used to verify that the document is not altered and can be trusted.

These flaws are not high in severity, but the consequences can be serious once the flaw gets exploited and signatures are forged in document macros. Signing the random document and faking its legitimacy is the way to trick users into allowing the macros and running malicious code.[3]

  • CVE-2021-41830/ CVE-2021-25633. The content and macro manipulation flaw with double certificate attack.
  • CVE-2021-41831/ CVE-2021-25634. The timestamp manipulation with signature wrapping.
  • CVE-2021-41832/ CVE-2021-25635.[4] Content manipulation with certificate validation attack.

If these flaws get successfully used and permit the attacker to timestamp the document, alter the contents, the document can be used as a trustworthy piece. Attackers can inject other algorithms into these documents and sign them, suggesting that they are not tampered with and signed by a trusted party.

Weaknesses have been fixed with the newest versions

The CVE-2021-41832 flaw tracked in the OpenOffice was disclosed by four researchers from the Ruhr University Bochum. The same flaw was known as the CVE-2021-25635 vulnerability in LibreOffice. Users who use the open-source office suites should upgrade to the latest available versions right away to avoid any consequences. For OpenOffice, it should be 4.1.10 and later, and for LibreOffice, 7.0.5, 7.1.1, or later.

These upgrades need to be done manually because applications do not offer the auto-updating feature. Download the latest versions from particular download centers.[5][6] You can also disable the macro function[7] if the updating is not happening or is not possible. Avoid trusting any random documents with macros. If you are still running the older versions, do not rely on the trusted list function. It is not a severe flaw, but laced and malicious documents can appear as coming from trusted sources.

Malicious macros can easily get used by criminals

Macro malware is the threat type that can be hidden in the Office files like Word or Excel. These files usually get delivered in malicious email campaigns and attached to messages or inside the ZIP files. These are common vectors for infections like ransomware because the payload of the virus can get triggered once macros get enabled on the document.

This type of malware made a comeback, and identifying these threats became very important since the ransomware aims at large businesses, companies, and everyday users. Phishing emails can easily transmit these attachments, and the text in the email requests the person to open the document and view the sensitive content that leads to run off the macro. This is the start of malware code injection into the VBA that begins to cause the infection.

Commonly, when the macro is already set to act maliciously and is included in the particular campaign, these are the signs that users can look out for and be suspicious of:

  • unknown senders;
  • random emails from unfamiliar or unrelated companies;
  • emails with details on unfamiliar purchases;
  • subject lines like "confidential", "project", "invoice", "order details";
  • documents with preview mode;
  • files with the suspicious process of macros.

Apache had another vulnerability discovered recently.[8] The vulnerability revealed that it could allow the remote code execution for unauthorized actors once exploited. Upgrades of software and applications occasionally are always recommended especially, since many developers do not come forward with their or third-party research findings.

Frequently asked questions

Is LibreOffice safe to use in 2026?

Yes, as long as you keep it updated and download it from libreoffice.org.{6} The project still publishes security advisories, and its October 5, 2026 fixes, including one for remote code execution, are in versions 26.2.5 and 26.8.0.{9} Older versions carry known flaws, so update before you open files from others.

Is LibreOffice malware?

No. LibreOffice itself is legitimate open source software. The risk comes from fake copies on look-alike download sites and from malicious documents that abuse old, unpatched versions.{9} Download only from the official site and keep macros disabled unless you trust the file completely.

Which gets security updates more often, LibreOffice or Apache OpenOffice?

LibreOffice does, based on what we read. It announced new advisories in both September and October 2026.{9} Apache OpenOffice's bulletin lists 4.1.16 as its latest security release, fixing seven 2025-numbered flaws.{10} If security updates matter to you, LibreOffice is the more actively patched suite.

How do I enable macros in LibreOffice or OpenOffice?

Open the macro security setting in the program options, then choose a lower level or add a trusted folder; the official help pages show the exact menu for your version. Do this only for files you created or fully trust. Malicious macros in email attachments remain a common way to spread malware, so keep the level high by default.{7}

Should I disable LibreOffice automatic update checks?

We advise against it. The update check is how most people learn about versions that fix flaws like the ones announced in 2026.{9} If you manage many computers centrally, replace it with your own update process rather than simply turning it off.

Are fake OpenOffice downloads dangerous?

Yes. Copies of free software on unofficial sites can bundle adware or malware with the real installer. Get Apache OpenOffice only from openoffice.org.{5} If you installed it from another site, uninstall it, scan your computer and reinstall from the official page.

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year