Microsoft has confirmed that Excel KB5002914 can make paste operations fail without an error in Excel 2016, 2019, 2021 and 2024. The September 8 security update fixes eight disclosed Excel vulnerabilities, but the acknowledged regression creates an awkward choice for IT teams: keep a security update installed while a core spreadsheet action may stop working, or accept the risk of a controlled rollback while Microsoft investigates.
What Excel KB5002914 changes
Excel KB5002914 is a security update for the MSI-based edition of Excel 2016. Microsoft says it addresses several remote-code-execution and information-disclosure vulnerabilities, and distributes separate 32-bit and 64-bit installers. The same support notice now carries the known-issue warning across newer perpetual Excel versions as well.
The failure is unusually easy to miss. A user copies a cell or range, chooses a destination and pastes, but the source remains selected and the destination does not change. Microsoft says Excel may provide no audible or visual error, which means a user can continue working without immediately realising that expected data was never inserted.
| Question | Confirmed answer |
|---|---|
| When was the update disclosed? | September 8, 2026 |
| Which versions are named? | Excel 2016, 2019, 2021 and 2024 |
| What can fail? | Paste may silently leave the destination unchanged |
| Permanent fix available? | Not yet; Microsoft says it is investigating |
Why the silent failure matters
A visible crash is disruptive, but a silent data-handling failure is harder to control. In finance, operations and reporting workflows, pasted ranges often feed formulas, reconciliations or uploads. If the destination is unchanged, an old value may survive and look plausible. The practical control is verification: users handling important work should confirm the destination changed and recheck totals before saving or exporting.
BleepingComputer reported user complaints about copy-and-paste and formula dragging shortly after Patch Tuesday. Born’s Tech and Windows World separately documented reports across MSI and Click-to-Run installations. Those reports help establish operational impact, but Microsoft’s support page remains the authoritative source for the confirmed scope and repair status.
What administrators should do now
Microsoft has not provided a universal workaround in the support article. That matters because uninstalling a security update also removes fixes for serious vulnerabilities. Administrators should inventory the affected Excel editions, reproduce the failure on a test ring and follow Microsoft’s support page for a corrected build. Any rollback should be time-limited, approved by security owners and paired with compensating controls.
This is the same release-management problem seen when a Microsoft RDS update forced triage and when Microsoft turned AI safety controls into an operational standard: deployment speed is only useful when validation can catch the consequence. For Excel KB5002914, the key acceptance test is simple—copy a representative range, paste it, and verify the destination and dependent calculations.
Frequently asked questions
What is Excel KB5002914?
It is Microsoft’s September 8, 2026 security update for Excel 2016 MSI installations. Microsoft’s notice also identifies a known paste failure affecting Excel 2016, 2019, 2021 and 2024.
Does Microsoft have a permanent fix?
No permanent fix was listed when checked. Microsoft says it is researching the issue and will update the support article.
Should every organisation uninstall the update?
No. A blanket rollback can restore vulnerabilities fixed by the security update. Organisations should test, assess exposure and follow their security change process.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



