EIGHT CVEs were disclosed by the Apache Software Foundation on 2 October 2026, spanning Apache OpenOffice, the Apache Directory LDAP API, and Apache Traffic Server. The most urgent issue is CVE-2026-59265 in Apache OpenOffice, which can trigger arbitrary code execution when a user opens a crafted document. OpenOffice has not yet released a final patch; the fix is version 4.1.17, which at the time was still a release candidate. The LDAP API and Traffic Server advisories are already available, with mitigations and updated builds published for each project.
OpenOffice users are advised to disable the Java runtime integration in the Preferences and avoid opening untrusted files, while awaiting the 4.1.17 release. For the LDAP API, six CVEs—most critically CVE-2026-103877 (a deserialization bug that could enable remote code execution) and CVE-2026-103552 (an unauthenticated stack overflow via nested search filters)—affect the API in both the 2.1.0–2.1.9 and 1.2.0–1.2.9 streams.
Other issues include CVE-2026-102731 (memory growth attack), CVE-2026-102795 (SNI-to-Host header policy enforcement), and CVE-2026-103878 (plain-text data leakage during StartTLS). Apache Traffic Server is impacted by CVE-2026-102795, an improper access control flaw affecting 9.0.0–9.2.14 and 10.0.0–10.1.3.
Patch guidance is straightforward: OpenOffice 4.1.17 when released, LDAP API updates to 2.1.9 or 1.2.9, and Traffic Server upgrades to 9.2.15 or 10.1.4. At present, no exploitation in the wild has been publicly confirmed for these flaws. The advisory emphasises applying updates promptly to mitigate potential impact.