Excel users hit by the September 2026 update have a particularly disruptive problem: copy appears to work, but paste can do nothing at all. Microsoft acknowledged the issue in the KB5002914 known-issues documentation, while reports also linked the regression to autofill and dragging formulas with the fill handle.
4
5
What Microsoft confirmed
The confirmed symptom is a silent paste failure. A user copies a cell or range and attempts to paste it, but the source remains selected and the destination remains unchanged. Excel provides no beep, error, or other visible indication that the paste failed.
4
5
Microsoft’s documented known issue names Excel 2024, 2021, 2019, and 2016. Reports from affected users additionally describe failures involving autofill and formula dragging.
4
5
A crucial KB5002914 scope detail
KB5002914 is the September 8, 2026 security update for Excel 2016, including MSI-based installations. Microsoft’s Office update index lists it under Excel 2016, and the Microsoft Update Catalog describes 32-bit and 64-bit Excel 2016 packages.
17
28
29
57
That does not mean reports involving newer Excel releases should be dismissed. Microsoft’s known-issue language and reporting identify Excel 2016 through 2024 as affected. But for IT teams, it is important not to assume that every affected Click-to-Run or newer Office installation received the same standalone KB5002914 package; the remediation path may instead involve its Office build.
3
5
The practical workaround—and why it needs caution
Affected users reported that uninstalling KB5002914 on MSI-based Office installations, or rolling back the Office build where applicable, restored normal copy-and-paste behavior.
5
8
However, this is not a consequence-free repair. Microsoft says KB5002914 addresses Excel remote-code-execution and information-disclosure vulnerabilities, and its documentation lists related advisories including CVE-2026-81399, CVE-2026-81390, CVE-2026-81954, and CVE-2026-81387.
17
A sensible response is to:
- Confirm the symptom with a simple copy-and-paste test before changing the deployment.
- Identify the installation type and update/build on the affected device; the standalone KB applies to Excel 2016, while other Office installations may have a build-based update path.
- Limit any rollback or uninstall to systems where the workflow impact warrants the exposure.
- Document the exception and monitor for a corrected Microsoft update, then restore the security update promptly.
Avoid unsupported workarounds such as manually replacing application executables. Those approaches can create stability, support, and security problems.
8
Was there an official fix?
Microsoft had acknowledged the paste failure, but the available reporting through September 15, 2026 did not identify an official hotfix or Microsoft workaround for the Excel regression. The uninstall or rollback approach was therefore a user-reported operational mitigation, not a Microsoft-issued repair.
5
7
15
How the Excel issue fits the September Patch Tuesday problems
The Excel regression occurred during a Patch Tuesday cycle that also produced separate Windows problems. Microsoft released out-of-band Windows updates on September 14 to address Remote Desktop Services failures, Hyper-V-based Linux virtual-machine folder-sharing issues, and some USB audio problems.
31
32
48
Those Windows fixes should not be confused with an Excel fix: they address different products and updates. The common lesson is operational rather than technical causation—security-update deployment needs validation, especially for business-critical workflows.
There is also insufficient evidence in the provided reporting to treat an email-related regression as part of the confirmed KB5002914 incident. It should not be grouped with this Excel bug without a specific advisory or reliable report.
Bottom line
The key risk is not merely that paste stops working; it can fail without telling the user, potentially leaving spreadsheets incomplete or inconsistent. Organizations that remove the update to restore Excel functionality should make that a temporary, controlled exception because the update was intended to address security vulnerabilities.
4
17