Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel
Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.
Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.
Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections
Microsoft's September 2026 Windows 11 update KB5124008 breaks certificate-based Always On VPN on some enterprise clients, forcing admins to pause rollout.
Microsoft's September 8, 2026 cumulative update KB5124008 for Windows 11 24H2 (build 26100.9445) and 25H2 (build 26200.9445) breaks certificate-based Always On VPN tunnels on some enterprise clients, with connectivity restored after uninstalling the update and rebooting. The issue was first detailed on Microsoft Q&A on September 9 by an administrator using Intune-deployed VPN profiles with RRAS and NPS on Windows Server 2019. The same mandatory Patch Tuesday package fixes two actively exploited zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, so many teams are pausing only VPN cohorts rather than blocking the full rollout.
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex patched multiple undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0, urging all users to update immediately.
Plex released fixes in Plex Media Server 1.43.3 and Plex Desktop 1.115.0 for multiple undisclosed security flaws, with CVE identifiers requested and details not yet published. Censys data shows more than 360,000 devices expose the Plex Media Server web interface. Past Plex flaws saw real exploitation, including CVE-2020-5741 (CVSS 7.2), used to implant a keylogger on a LastPass employee's home computer during the 2022 breach, and CVE-2025-34158 (CVSS 8.5), an authentication bug patched in August 2025.