OpenOffice flaw could let attacker take over system
The vulnerability affects versions before 4.1.17 and could allow arbitrary code execution, according to security agencies.
A vulnerability has been reported in Apache OpenOffice that could potentially give an attacker full control of a computer after a malicious document is opened. The problem is registered as CVE-2026-59265.
Apache OpenOffice's security bulletin reports that opening a manipulated document could lead to a system takeover. CERT-FR, the French government agency for digital security, classifies the risk as the remote execution of arbitrary code.
According to CERT-FR, versions older than 4.1.17 are affected. OpenOffice's public security page lists the vulnerability for version 4.1.16. Users and administrators should therefore check their installed version number and follow the developers' instructions.
According to the available descriptions, an attacker does not need to gain access to the operating system first. The risk arises when a user opens a specially prepared document. This could happen, for example, through an email attachment, a download or a document shared via a collaboration environment.
The sources consulted do not make clear whether the vulnerability is already being actively exploited. Nor has it been established how many Dutch users are running an affected version. The report therefore does not mean that every OpenOffice installation has been taken over, but it does mean that organisations should not treat the risk as merely theoretical.
The safest practical step is not to open documents from unknown senders and to update OpenOffice only through official channels. Organisations that manage OpenOffice centrally can also inventory which versions are active and temporarily impose additional restrictions in line with their own security policy.
Tweakers reports that Dutch researchers independently came across the same problem. Little information about their technical findings and the precise relationship to the official report is available in publicly accessible primary sources. We are therefore limiting ourselves to the vulnerability and its confirmed consequences.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical core has been confirmed by the supplier and an independent government agency. Matters that remain unknown, such as active exploitation and the number of Dutch users, have not been presented as facts.
- confirmed CVE-2026-59265 could lead to a system takeover when a malicious document is opened. — This is stated in Apache OpenOffice's security bulletin. source
- confirmed Versions before 4.1.17 are affected. — CERT-FR names OpenOffice versions older than 4.1.17 as affected systems. source
- uncertain The available sources confirm active exploitation of the flaw. — The bulletins consulted report the vulnerability, but no confirmed exploitation in the wild. source
- uncertain Dutch researchers independently discovered the same problem. — This is stated in the supplied Tweakers headline, but the technical details could not be verified in a publicly available primary source. source
Editor's note
The vulnerability and the risk of arbitrary code execution have been confirmed by Apache OpenOffice and CERT-FR. Details about the independent Dutch discoveries and possible exploitation are absent from public primary sources.Sources
- Apache OpenOffice Security Team Bulletin — Apache OpenOffice
- Multiples vulnérabilités dans OpenOffice — CERT-FR
- CVE-2026-59265 — CVE Program
More on this in Dutch media
- De Telegraaf — „openoffice cybersecurity”
- de Volkskrant — „openoffice cybersecurity”
- NOS — „openoffice cybersecurity”