Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft's September Patch Tuesday update KB5002914 breaks copy-and-paste and formula dragging in Excel 2016 through 2024; uninstalling the update restores functionality.
Users on Reddit and Microsoft Q&A report that the KB5002914 security update shipped in the September 2026 Patch Tuesday breaks copy-and-paste, autofill, and formula dragging in Excel. The problem spans Office 2016 through 2024 across MSI and Click-to-Run installations, including Office LTSC Standard 2021, with some teams blocked after widespread patching. Uninstalling KB5002914 or downgrading the Office build restores functionality, though replacing the excel.exe binary is not recommended. BleepingComputer could not reproduce the issue on Excel 2019 Version 2508 Build 19127.20302 and contacted Microsoft for comment.
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability
Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.
Cisco RoomOS Stack Overflow Vulnerability
Cisco fixed a stack overflow in the RoomOS USB driver allowing physical-access attackers to execute code with root privileges.
Insufficient boundary checks in the USB driver of Cisco RoomOS allow a buffer overflow when specific data is supplied through the USB port. An unauthenticated local attacker with physical access can connect a malicious USB device and execute arbitrary code with root privileges. Cisco has released software updates and no workarounds address the issue.