A Security Patch That Broke a Core Feature
Microsoft's September 2026 security update, KB5002914, introduced a code regression that silently broke copy-and-paste, autofill, and formula dragging in Excel. Rather than throwing an error, the bug fails quietly: as Microsoft describes it, "Although users try to paste content, the source remains selected and the destination is unmodified."
The regression affected Excel 2016, 2019, 2021, 2024, and Excel Online, making it one of the broader-reaching side effects from this month's Patch Tuesday cycle.
The Fix — With a Catch
Microsoft released KB5002655 on September 18, 2026 to address the issue, but the fix currently only covers the MSI-based edition of Office 2016. Click-to-Run installations — including Microsoft 365 Home and other subscription-based Office deployments — are not yet covered by this specific patch. Microsoft says it continues working on permanent fixes for the other affected Excel versions.
Options for Affected Users
Until a full fix rolls out across all affected versions, users have three ways to work around the issue:
- Install KB5002655 — resolves the issue for MSI-based Office 2016 editions
- Use Paste Special (
Ctrl+Alt+V) — lets you manually select and apply the paste option instead of relying on standard copy-paste - Uninstall KB5002914 — restores normal copy-paste behavior, but also removes the security fixes that update shipped with, which is not recommended for systems facing active threats
For most organizations, applying KB5002655 where available — or switching to Paste Special as a stopgap on unpatched Click-to-Run installs — is the safer path, since rolling back a security update reopens whatever vulnerabilities KB5002914 was issued to close.