ZeroHour
Story · 2 sources · 3 articlesfirst updated ()

Microsoft confirms KB5002914 Excel security update silently breaks copy and paste

What's new: New story: Microsoft publicly confirmed a known issue in the September 8, 2026 KB5002914 Excel security update that silently breaks copy-paste, autofill, and formula dragging in Excel 2016-2024, with uninstalling the update as the only confirmed workaround pending a fix.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Microsoft confirmed the September 8, 2026 KB5002914 Excel security update silently breaks copy-paste, autofill, and formula dragging in Excel 2016 through 2024; the only confirmed fix is uninstalling the update, which removes the month's security patches.

Microsoft has added a known issue to KB5002914, the September 8, 2026 Patch Tuesday security update for Excel, confirming that after installation, copy-paste, autofill, and formula dragging fail silently in Excel 2016, 2019, 2021, and 2024. Failed operations produce no beep or error message, and the destination is left unmodified. The update was released to address remote code execution and information disclosure flaws, including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. As of September 15, 2026, no hotfix date has been published, and the only widely confirmed recovery is uninstalling or rolling back KB5002914 (Report 1 names OfficeC2RClient or Oarpmany as uninstall methods), which restores functionality but drops the September Excel security fixes, forcing administrators to choose between usability and patching. No disagreements between sources were found on the affected versions, symptoms, or workaround; Report 1 describes the patched flaws generically as RCE issues, while Report 2 specifies RCE and information disclosure flaws with CVE identifiers.

  • KB5002914 is the September 8, 2026 Patch Tuesday security update for Excel
  • Known issue affects Excel 2016, 2019, 2021, and 2024
  • Copy-paste, autofill, and formula dragging fail silently with no beep or error message, leaving the destination unmodified
  • The update patches remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954
  • Workaround: uninstalling or rolling back KB5002914 (e.g., via OfficeC2RClient or Oarpmany) restores functionality but removes September's Excel security fixes
  • No hotfix date announced as of September 15, 2026

Coverage timeline

  1. · 3d ago
    BleepingComputer· 20
    Microsoft confirms KB5002914 Excel update breaks copy and paste

    Microsoft confirms KB5002914 Office security update silently breaks copy-paste, autofill, and formula dragging in Excel 2016 through 2024.

  2. · 3d ago
    Cyber Security News· 35
    Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

    Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

  3. · 7h ago
    BleepingComputer· 15
    Microsoft fixes broken copy and paste for Excel 2016 users

    Microsoft released KB5002655 fixing silent copy-and-paste failures in Excel 2016 caused by the September 2026 KB5002914 security update.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81954
+2 in the same advisory: …81390 …81399
Use-After-Free Code Execution Flaw in Microsoft Excel (Office 2016-2024)

CVE-2026-81954 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office Excel, rated 7.8 (High) under CVSS 3.1, that allows an unauthorized attacker to execute code locally. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation requires no credentials or privileges but does require user interaction - in practice, getting a user to open a specially crafted spreadsheet file on a vulnerable Excel installation. If successful, the attacker's code runs in the context of the signed-in user, with high impact on confidentiality, integrity and availability of that machine (e.g., malware deployment, data theft, or a foothold for lateral movement on a corporate endpoint). Users of Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021 and 2024 releases that include Excel are affected, per the listed CPE data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

Do: Apply Microsoft's security update for CVE-2026-81954 via the Microsoft 365 Apps/Office update channel (or your WSUS/SCCM deployment pipeline) and verify installed Office builds against the affected and patched versions listed in Microsoft's advisory, which is the authoritative source for exact version ranges. Until patched, keep Office Protected View and Mark-of-the-Web enforcement enabled, treat unsolicited or unexpected spreadsheet attachments with caution, and monitor Microsoft's advisory for any update to exploitation status.

7.8
group max
<1%
  • Microsoft Excel (affected component across listed Office SKUs)
  • Microsoft 365 Apps
  • Microsoft 365
  • +4 more
masshundreds of millions of users (Microsoft 365 alone exceeds 400M paid commercial seats, plus the installed base of perpetual Office desktop releases)