HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium Advisory

Microsoft Patch KB5002914 Breaks Copy‑Paste in Excel 2016, Fix Released via KB5002665

A September 2026 security update (KB5002914) broke copy‑and‑paste in Excel 2016, prompting Microsoft to release KB5002665 as a fix. The incident highlights the importance of change‑management controls and evidence collection for audit readiness.

Verisq™ Intelligence · 📅 September 18, 2026 · 📰 bleepingcomputer.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Microsoft Patch KB5002914 Breaks Copy‑Paste in Excel 2016, Fix Released via KB5002665

What Happened — The September 2026 security update KB5002914 caused copy‑and‑paste, autofill, and formula‑dragging operations to fail silently in Microsoft Excel 2016 (MSI‑based edition). Microsoft released a corrective update KB5002665 that restores the functionality for the affected edition.

Why It Matters for Trust & Control Assurance

  • Functional regressions after a security patch illustrate the need for change‑management controls that require testing and validation before production rollout.
  • Continuous control‑assurance programs must capture evidence of patch verification and maintain a rollback plan to preserve audit‑ready evidence of remediation.
  • The incident maps to the control objective of ensuring the effectiveness of configuration and change controls, a single control that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected — Enterprises and end‑users across all sectors that rely on Excel 2016 (MSI edition), particularly finance, engineering, and government offices that depend on spreadsheet automation.

Recommended Actions

  • Deploy the KB5002665 fix to affected machines; verify remediation in a test environment before full rollout.
  • Document the regression, the mitigation steps, and the rollback procedure as part of your change‑management evidence.
  • Update your patch‑validation SOPs to include functional testing of critical productivity tools after each security update.

Source: BleepingComputer

Technical Notes

  • The regression stems from a code change in the September 2026 security update (KB5002914).
  • The issue affects Excel 2016 MSI, Excel 2019/2021/2024, and Excel Online, but the fix currently only covers the MSI edition.
  • Uninstalling KB5002914 restores functionality but also removes critical security patches for remote‑code‑execution vulnerabilities.

Source: Microsoft support documentation

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-copy-and-paste-for-excel-2016-users/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →