As reported by BleepingComputer, Microsoft has issued KB5002655 to address a code regression introduced by the September 2026 KB5002914 security update that silently broke copy-and-paste, autofill, and formula dragging across Excel Online and Excel 2016 through 2024. However, the fix currently applies only to the MSI-based edition of Office 2016 — leaving the majority of affected deployments without a permanent resolution.

Security Impact: As reported by BleepingComputer, Microsoft has issued KB5002655 to address a code regression introduced by the September 2026 KB5002914 security update that silently broke copy-and-paste, autofill, and formula dragging across Excel Online and Excel 2016 through 2024.

Why This Matters Beyond a Nuisance

At first glance, a broken paste function sounds like a productivity complaint, not a security story. The real risk, however, lies in how organizations respond. When critical business workflows break and the vendor's fix doesn't cover their edition, IT teams face intense pressure to uninstall the offending security update. Microsoft's own documentation confirms that removing KB5002914 strips away patches for remote code execution and information disclosure vulnerabilities — exactly the class of flaws threat actors prioritize for initial access and lateral movement.

This creates a predictable and dangerous pattern: a regression in a security patch erodes trust in the patching process, leading to delayed or reversed updates that leave endpoints exposed to known, patched vulnerabilities. In enterprise environments where Excel is mission-critical for finance, operations, and analytics teams, the pressure to restore functionality quickly can override patch discipline.

The Exposure Gap

ItemDetail
Trigger UpdateKB5002914 (September 2026 security update)
Affected ProductsExcel Online; Excel 2016, 2019, 2021, 2024 (MSI and Click-to-Run)
SymptomSilent paste failures — no error, no beep, destination unchanged
Current FixKB5002655 — only for Office 2016 MSI-based editions
Unfixed EditionsOffice 2016 Click-to-Run, Office 2019, 2021, 2024, Excel Online
Known Remaining IssueSome conditional formatting scenarios still impacted
Vendor WorkaroundPaste Special (Ctrl+Alt+V) — does not address all scenarios

The Broader Patch Quality Problem

This incident is part of a recurring pattern where Microsoft's monthly security updates introduce functional regressions that disproportionately affect legacy Office editions still widely deployed in regulated industries, government agencies, and enterprises with long upgrade cycles. Office 2016 reached end of mainstream support, yet remains common in environments where application compatibility testing is slow and expensive.

For defenders, the takeaway isn't just about this specific bug — it's about the need for a structured regression-testing process before deploying monthly updates at scale, and for having decision frameworks in place when functionality breaks collide with security obligations.

Shield53 Recommendations

Shield53 Recommendations
Do not uninstall KB5002914. The security patches it carries for RCE and information disclosure vulnerabilities outweigh the paste-functionality impact. Use the Paste Special workaround (Ctrl+Alt+V) as an interim mitigation for affected users.
Deploy KB5002655 immediately if you run MSI-based Office 2016. Verify via update history in Control Panel or the Microsoft Update Catalog.
For Click-to-Run and newer Office editions: monitor Microsoft's support documentation for an expanded fix. Escalate to Microsoft Support if business impact is significant — vendor prioritization often follows customer pressure.
Communicate proactively with end users. Provide a one-page guide on the Paste Special workaround and set expectations for the permanent fix timeline. Silent failures are especially frustrating because users believe they made an error.
Implement pre-deployment regression testing for monthly Office updates in a pilot group representing real-world workflows — particularly finance and data-analysis teams that rely heavily on paste, autofill, and formula dragging.
Document the risk decision if any team pushes to roll back the security update. Record the specific vulnerabilities being re-exposed and require sign-off from both security leadership and the business unit requesting the rollback.
Accelerate Office version modernization where feasible. Legacy editions receive slower fixes and fewer guarantees, widening the window between regression and remediation.
The real vulnerability here isn't a CVE — it's the organizational tendency to trade long-term security posture for short-term productivity relief when patch quality falters. Defenders need pre-built decision frameworks, not ad hoc trade-offs made under pressure.