ZeroHour
Story · 2 sources · 3 articlesfirst updated ()

Microsoft confirms KB5002914 September 2026 Excel update breaks copy and paste; no hotfix date yet

What's new: Cyber Security News reported on September 15, 2026 that Microsoft formally added the copy-paste breakage to KB5002914's known issues and identified the specific flaws the update patches: CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954 (remote code execution and information disclosure). The report also confirmed that no hotfix date has been announced as of September 15, 2026, and highlighted…
Merged summary · glm-5.3 · rewritten as coverage arrives

Microsoft has confirmed that KB5002914, the September 8, 2026 Patch Tuesday Excel security update, silently breaks paste, autofill, and formula dragging in Excel 2016 through 2024; uninstalling the update is the only confirmed workaround, which forgoes this…

Microsoft confirmed that the KB5002914 security update, shipped September 8, 2026 as part of Patch Tuesday, breaks copy-and-paste, autofill, and formula dragging in Excel 2016, 2019, 2021, and 2024. The failures occur silently, with no beep or error message, leaving destination cells unmodified. Microsoft has added the issue to KB5002914's known issues and is investigating, but as of September 15, 2026, no hotfix date has been published. The only widely confirmed recovery is uninstalling KB5002914 (via OfficeC2RClient or Oarpmany) or downgrading the Office build, which restores functionality but removes this month's Excel security fixes. The update addressed remote code execution and information disclosure flaws, including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954, forcing admins to choose between usability and security. Earlier user reports on Reddit and Microsoft Q&A, first covered by BleepingComputer on September 10, 2026, spanned Office 2016 through 2024 across MSI and Click-to-Run installations, including Office LTSC Standard 2021, with some teams blocked after widespread patching. BleepingComputer could not reproduce the issue on Excel 2019 Version 2508 Build 19127.20302; replacing the excel.exe binary is not recommended as a workaround.

  • KB5002914 is the September 8, 2026 Patch Tuesday Excel security update
  • Microsoft confirmed the update breaks paste, autofill, and formula dragging in Excel 2016, 2019, 2021, and 2024
  • Failures occur silently with no beep or error message; destination cells are left unmodified
  • Affects MSI and Click-to-Run installations, including Office LTSC Standard 2021
  • The update fixes remote code execution and information disclosure flaws CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954
  • Only confirmed recovery is uninstalling KB5002914 via OfficeC2RClient or Oarpmany, or downgrading the Office build
  • No hotfix date published as of September 15, 2026; Microsoft is investigating
  • BleepingComputer could not reproduce the issue on Excel 2019 Version 2508 Build 19127.20302

Coverage timeline

  1. · 5d ago
    BleepingComputer· 22
    Microsoft Excel KB5002914 update breaks copy and paste for some users

    Microsoft's September Patch Tuesday update KB5002914 breaks copy-and-paste and formula dragging in Excel 2016 through 2024; uninstalling the update restores functionality.

  2. · 13h ago
    BleepingComputer· 20
    Microsoft confirms KB5002914 Excel update breaks copy and paste

    Microsoft confirms KB5002914 Office security update silently breaks copy-paste, autofill, and formula dragging in Excel 2016 through 2024.

  3. · 12h ago
    Cyber Security News· 35
    Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

    Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81954
+2 in the same advisory: …81390 …81399
Use-After-Free Code Execution Flaw in Microsoft Excel (Office 2016-2024)

CVE-2026-81954 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Excel, rated 7.8 (High) under CVSS 3.1, that allows an unauthorized attacker to execute code locally. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires no credentials or privileges but does require user interaction - in practice, getting a user to open a specially crafted spreadsheet file on a vulnerable Excel installation. If successful, the attacker's code runs in the context of the signed-in user, with high impact on confidentiality, integrity and availability of that machine (e.g., malware deployment, data theft, or a foothold for lateral movement on a corporate endpoint). Users of Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021 and 2024 releases that include Excel are affected, per the listed CPE data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

Do: Apply Microsoft's security update for CVE-2026-81954 via the Microsoft 365 Apps/Office update channel (or your WSUS/SCCM deployment pipeline) and verify installed Office builds against the affected and patched versions listed in Microsoft's advisory, which is the authoritative source for exact version ranges. Until patched, keep Office Protected View and Mark-of-the-Web enforcement enabled, treat unsolicited or unexpected spreadsheet attachments with caution, and monitor Microsoft's advisory for any update to exploitation status.

7.8
group max
<1%
  • Microsoft Excel (affected component across listed Office SKUs)
  • Microsoft 365 Apps
  • Microsoft 365
  • +4 more
masshundreds of millions of users (Microsoft 365 alone exceeds 400M paid commercial seats, plus the installed base of perpetual Office desktop releases)