Microsoft confirmed that Office security update KB5002914 can cause Microsoft Excel copy-and-paste actions to fail silently: the source cells remain selected, but no content appears at the destination and no error is displayed. The defect also disrupts formula dragging and autofill, affecting Excel 2016, 2019, 2021, and 2024 across MSI, Click-to-Run, and reported Office LTSC Standard 2021 deployments.
KB5002914 delivers fixes for Excel remote-code-execution and information-disclosure vulnerabilities, leaving organizations to weigh spreadsheet availability against retaining the September security protections. Microsoft has acknowledged the issue and is investigating, but has not provided a hotfix timeline; current mitigations are uninstalling the update on MSI installations or rolling back the Office build for Click-to-Run deployments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft released KB5002914 for Excel 2016 as part of its September 2026 security updates. The update replaced KB5002886 and addressed Excel remote-code-execution and information-disclosure vulnerabilities.
Affected users reported that uninstalling KB5002914 from MSI installations or rolling back Click-to-Run Office builds restored Excel functionality. These mitigations remove the security improvements delivered by the September update.
Microsoft acknowledged the KB5002914 defect in its known-issues documentation and said it was investigating the problem. The issue was reported in MSI, Click-to-Run, and Office LTSC Standard 2021 deployments, with no error, beep, or other warning presented to affected users.
Following deployment of KB5002914, users reported that Excel copy-and-paste could fail silently, leaving the source selected and destination unchanged. Reports also described broken autofill and formula-dragging functions across Excel 2016, 2019, 2021, and 2024.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceghacks.net
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.