← Back to CVE intelligence
CVE intelligence

CVE-2026-63276

Vulnerability intelligence

Published Sep 22, 2026Sources checked Oct 5, 2026
5.4MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-63276 and is rated Medium severity with a CVSS score of 5.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

What to do next

Remediation and response

Ubuntu Security Notices guidance

Vendor revision: Oct 5, 2026

(CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-63276?

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph emitting many operators wrote past the end of the buffer. In fixed versions the remaining capacity is tracked and the conversion stops when it is used up.

Source: NVD