Notice USN-8868-1, published by Ubuntu Security on 5 October 2026, describes several vulnerabilities in LibreOffice. According to the text, the program mishandled importing WMF and PICT images, importing PDF documents, embedded CFF fonts in documents and package URLs, and improperly mitigated out-of-bounds writes caused by Graphite font actions. Depending on the case, an attacker could possibly crash the program for denial of service, execute arbitrary code or obtain sensitive information.
The listed identifiers are CVE-2026-63272, CVE-2026-63273, CVE-2026-63274, CVE-2026-63275, CVE-2026-63276, CVE-2026-63278, CVE-2026-63279 and CVE-2026-50593. The available text is an automatic translation of the Ubuntu Security feed. For affected versions, fixed packages and exact wording, consult the original notice on the official Ubuntu Security page referenced in the source.
The practical response is to apply the LibreOffice updates supplied by your distribution and, until patched, avoid opening files from unknown senders. If you use AI to study this notice, use only the identifiers and public excerpts, not internal documents.