Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel
Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.
Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.
- Paste, autofill, and formula dragging fail silently across Excel 2016 through 2024
- Update patches Excel RCE and info disclosure flaws CVE-2026-81399, CVE-2026-81390, CVE-2026-81954
- Only confirmed recovery is uninstalling KB5002914, removing September security fixes
- No hotfix date announced as of September 15, 2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81954 | Use-After-Free Code Execution Flaw in Microsoft Excel (Office 2016-2024) CVE-2026-81954 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Excel, rated 7.8 (High) under CVSS 3.1, that allows an unauthorized attacker to execute code locally. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires no credentials or privileges but does require user interaction - in practice, getting a user to open a specially crafted spreadsheet file on a vulnerable Excel installation. If successful, the attacker's code runs in the context of the signed-in user, with high impact on confidentiality, integrity and availability of that machine (e.g., malware deployment, data theft, or a foothold for lateral movement on a corporate endpoint). Users of Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021 and 2024 releases that include Excel are affected, per the listed CPE data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days. Do: Apply Microsoft's security update for CVE-2026-81954 via the Microsoft 365 Apps/Office update channel (or your WSUS/SCCM deployment pipeline) and verify installed Office builds against the affected and patched versions listed in Microsoft's advisory, which is the authoritative source for exact version ranges. Until patched, keep Office Protected View and Mark-of-the-Web enforcement enabled, treat unsolicited or unexpected spreadsheet attachments with caution, and monitor Microsoft's advisory for any update to exploitation status. | 7.8 group max | <1% |
| masshundreds of millions of users (Microsoft 365 alone exceeds 400M paid commercial seats, plus the installed base of perpetual Office desktop releases) |
Full article484 words · extracted from cybersecuritynews.com · click to collapse
Microsoft has confirmed that the September 8, 2026 Excel security update KB5002914 can silently break copy and paste in Excel 2016, 2019, 2021, and 2024.
Microsoft added the defect to the update’s known issues after Patch Tuesday users reported that paste, autofill, and formula dragging failed with no error.
Microsoft’s advisory says the paste operation might fail silently. A user copies a cell or range, then pastes, but the source remains selected, and the destination never changes.
No beep or error message appears, so finance and operations staff may believe data transferred when the sheet is still empty. That lack of feedback is what makes the bug so easy to miss during routine spreadsheet work.
Reports on Reddit and Microsoft Q&A described the same behavior after the September 9 install wave, including broken drag-fill, with some teams already fully patched before anyone noticed.
Typing a few values, copying them, and pasting nearby is enough to confirm the bug. KB5002914 is a security release for Excel 2016 that addresses remote code execution
and information disclosure, tying to September CVEs such as CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. The standalone Microsoft Download Center packages apply only to MSI-based Office 2016, not Click-to-Run editions such as Microsoft 365 Home.
The update is also available from Microsoft Update and the Microsoft Update Catalog, and it replaces security update 5002886.
That mix of serious Excel flaws and a core productivity break is why administrators are now stuck between keeping the patch and keeping spreadsheets usable.
The public KB is written for Excel 2016, yet Microsoft’s known-issue note names Excel 2024, 2021, 2019, and 2016. Field reports also cover MSI and Click-to-Run installs and Office LTSC Standard 2021, pointing to a broader September Office servicing problem rather than a single 2016 MSI package.
Microsoft says it is researching the issue and will post more information when it becomes available, as detailed in the support advisory published by Microsoft. No hotfix date has been published as of September 15, 2026.
Until an official repair ships, the only widely confirmed recovery is to uninstall or roll back KB5002914. MSI customers say removal restores paste, while Click-to-Run sites have used XML or Group Policy to revert the Office build. Both moves drop the month’s Excel security fixes.
Replacing the updated excel.exe with an older binary is an unsupported folk workaround and can leave mixed files that create new security and stability gaps.
Teams that must restore Excel should document the exception, treat untrusted workbooks as high risk, and watch Microsoft’s KB5002914 advisory for an out-of-band fix.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/kb5002914-update-breaks-copy-paste/