Home › Intelligence › Brief
BREACH BRIEF🟡 Medium Advisory

Microsoft Patch KB5002914 Breaks Copy‑Paste in Excel 2016, Fix Released via KB5002665

A September 2026 security update (KB5002914) broke copy‑and‑paste in Excel 2016, prompting Microsoft to release KB5002665 as a fix. The incident highlights the importance of change‑management controls and evidence collection for audit readiness.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 bleepingcomputer.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Microsoft Patch KB5002914 Breaks Copy‑Paste in Excel 2016, Fix Released via KB5002665

What Happened — The September 2026 security update KB5002914 caused copy‑and‑paste, autofill, and formula‑dragging operations to fail silently in Microsoft Excel 2016 (MSI‑based edition). Microsoft released a corrective update KB5002665 that restores the functionality for the affected edition.

Why It Matters for Trust & Control Assurance

  • Functional regressions after a security patch illustrate the need for change‑management controls that require testing and validation before production rollout.
  • Continuous control‑assurance programs must capture evidence of patch verification and maintain a rollback plan to preserve audit‑ready evidence of remediation.
  • The incident maps to the control objective of ensuring the effectiveness of configuration and change controls, a single control that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected — Enterprises and end‑users across all sectors that rely on Excel 2016 (MSI edition), particularly finance, engineering, and government offices that depend on spreadsheet automation.

Recommended Actions

  • Deploy the KB5002665 fix to affected machines; verify remediation in a test environment before full rollout.
  • Document the regression, the mitigation steps, and the rollback procedure as part of your change‑management evidence.
  • Update your patch‑validation SOPs to include functional testing of critical productivity tools after each security update.

Source: BleepingComputer

Technical Notes

  • The regression stems from a code change in the September 2026 security update (KB5002914).
  • The issue affects Excel 2016 MSI, Excel 2019/2021/2024, and Excel Online, but the fix currently only covers the MSI edition.
  • Uninstalling KB5002914 restores functionality but also removes critical security patches for remote‑code‑execution vulnerabilities.

Source: Microsoft support documentation

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-copy-and-paste-for-excel-2016-users/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →