As reported by BleepingComputer, Microsoft has issued KB5002655 to address a code regression introduced by the September 2026 KB5002914 security update that silently broke copy-and-paste, autofill, and formula dragging across Excel Online and Excel 2016 through 2024. However, the fix currently applies only to the MSI-based edition of Office 2016 — leaving the majority of affected deployments without a permanent resolution.
Why This Matters Beyond a Nuisance
At first glance, a broken paste function sounds like a productivity complaint, not a security story. The real risk, however, lies in how organizations respond. When critical business workflows break and the vendor's fix doesn't cover their edition, IT teams face intense pressure to uninstall the offending security update. Microsoft's own documentation confirms that removing KB5002914 strips away patches for remote code execution and information disclosure vulnerabilities — exactly the class of flaws threat actors prioritize for initial access and lateral movement.
This creates a predictable and dangerous pattern: a regression in a security patch erodes trust in the patching process, leading to delayed or reversed updates that leave endpoints exposed to known, patched vulnerabilities. In enterprise environments where Excel is mission-critical for finance, operations, and analytics teams, the pressure to restore functionality quickly can override patch discipline.
The Exposure Gap
| Item | Detail |
|---|---|
| Trigger Update | KB5002914 (September 2026 security update) |
| Affected Products | Excel Online; Excel 2016, 2019, 2021, 2024 (MSI and Click-to-Run) |
| Symptom | Silent paste failures — no error, no beep, destination unchanged |
| Current Fix | KB5002655 — only for Office 2016 MSI-based editions |
| Unfixed Editions | Office 2016 Click-to-Run, Office 2019, 2021, 2024, Excel Online |
| Known Remaining Issue | Some conditional formatting scenarios still impacted |
| Vendor Workaround | Paste Special (Ctrl+Alt+V) — does not address all scenarios |
The Broader Patch Quality Problem
This incident is part of a recurring pattern where Microsoft's monthly security updates introduce functional regressions that disproportionately affect legacy Office editions still widely deployed in regulated industries, government agencies, and enterprises with long upgrade cycles. Office 2016 reached end of mainstream support, yet remains common in environments where application compatibility testing is slow and expensive.
For defenders, the takeaway isn't just about this specific bug — it's about the need for a structured regression-testing process before deploying monthly updates at scale, and for having decision frameworks in place when functionality breaks collide with security obligations.
Shield53 Recommendations
The real vulnerability here isn't a CVE — it's the organizational tendency to trade long-term security posture for short-term productivity relief when patch quality falters. Defenders need pre-built decision frameworks, not ad hoc trade-offs made under pressure.