Windows

Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

Microsoft has confirmed that the September 8, 2026 Excel security update KB5002914 can silently break copy and paste in Excel 2016, 2019, 2021, and 2024.

Microsoft added the defect to the update’s known issues after Patch Tuesday users reported that paste, autofill, and formula dragging failed with no error.

Microsoft’s advisory says the paste operation might fail silently. A user copies a cell or range, then pastes, but the source remains selected, and the destination never changes.

No beep or error message appears, so finance and operations staff may believe data transferred when the sheet is still empty. That lack of feedback is what makes the bug so easy to miss during routine spreadsheet work.

Reports on Reddit and Microsoft Q&A described the same behavior after the September 9 install wave, including broken drag-fill, with some teams already fully patched before anyone noticed.

Typing a few values, copying them, and pasting nearby is enough to confirm the bug. KB5002914 is a security release for Excel 2016 that addresses remote code execution

and information disclosure, tying to September CVEs such as CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. The standalone Microsoft Download Center packages apply only to MSI-based Office 2016, not Click-to-Run editions such as Microsoft 365 Home.

The update is also available from Microsoft Update and the Microsoft Update Catalog, and it replaces security update 5002886.

That mix of serious Excel flaws and a core productivity break is why administrators are now stuck between keeping the patch and keeping spreadsheets usable.

The public KB is written for Excel 2016, yet Microsoft’s known-issue note names Excel 2024, 2021, 2019, and 2016. Field reports also cover MSI and Click-to-Run installs and Office LTSC Standard 2021, pointing to a broader September Office servicing problem rather than a single 2016 MSI package.

Microsoft says it is researching the issue and will post more information when it becomes available, as detailed in the support advisory published by Microsoft. No hotfix date has been published as of September 15, 2026.

Until an official repair ships, the only widely confirmed recovery is to uninstall or roll back KB5002914. MSI customers say removal restores paste, while Click-to-Run sites have used XML or Group Policy to revert the Office build. Both moves drop the month’s Excel security fixes.

Replacing the updated excel.exe with an older binary is an unsupported folk workaround and can leave mixed files that create new security and stability gaps.

Teams that must restore Excel should document the exception, treat untrusted workbooks as high risk, and watch Microsoft’s KB5002914 advisory for an out-of-band fix.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago