Skip to main content
CybersecurityVulnerability Management

Microsoft Fixes Excel Copy-Paste Bug in Security Update

Person working at desk with laptop showing Excel spreadsheet.

"Although users try to paste content, the source remains selected and the destination is unmodified," Microsoft said when it confirmed these issues earlier this week, describing a silent failure that left some Excel users unable to copy and paste after installing the September 2026 security update.

How the bug presented and where it showed up

Following the rollout of the September 2026 update KB5002914, customers reported widespread copy-and-paste failures on the Microsoft Q&A forums and Reddit. Microsoft confirmed the problem and blamed it on a code regression. The vendor said affected operations—including paste, autofill, and formula dragging—fail without any audible or visual indication: "When this issue occurs, users receive no indication of the failure, such as a beep or error message."

Microsoft acknowledged the bug affects multiple deployments of Excel: Excel Online and Excel 2024, 2021, 2019, and 2016. That breadth made the issue immediately consequential for both cloud and installed Office users.

Microsoft's mitigation: KB5002655 and its narrow scope

Microsoft released update KB5002655 to mitigate the problem. In a support document published Wednesday, the company said, "This update fixes the known issue in KB5002914 that causes certain paste operations to fail silently." When BleepingComputer asked whether KB5002655 resolves the copy-and-paste shortcut bug, Microsoft reiterated the release and noted caveats around conditional formatting.

Crucially, Microsoft added that the KB5002655 fix applies only to the Microsoft Installer (.msi)-based edition of Office 2016 and "doesn't apply to Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home." In other words, users of Click-to-Run Office installations—and users of Excel Online and the 2019, 2021, and 2024 versions—remain without the vendor-supplied remedy.

Workarounds, rollback options, and their trade-offs

Until Microsoft ships a permanent solution for all affected Excel versions, the company advised impacted customers to use the Paste Special option. The steps Microsoft recommended are: open the Home tab, select the Paste drop-down, choose Paste Special, and then use the Ctrl+Alt+V keyboard shortcut to select an option such as Formula, Formula and number formats, Values, Values and number formats, or Paste Link.

Some users reported that uninstalling KB5002914 restores copy-and-paste functionality on impacted systems. Microsoft’s reporting flags a security trade-off: removing the update will also "remove a long list of patches for remote code execution and information disclosure vulnerabilities." The source provides explicit commands for rollback depending on Office edition:

  • Office 2016:

    "C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{{90160000-0012-0000-1000-0000000FF1CE}}" "{{27882596-A8ED-4382-9C71-6CD2DD19F732}}" "1033" "0"

  • Office 2019:

    "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /update user updatetoversion=16.0.10417.20197

  • Office 2021 & 2024:

    "C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe" /update user updatetoversion=16.0.20326.20132

Microsoft also warned it is "aware of some user scenarios impacted by conditional formatting" and recommended customers follow its guidance when applying the mitigation.

How Excel 2016 users, Click-to-Run/Home users, and IT teams are affected

Excel 2016 users who run the Microsoft Installer (.msi)-based edition have a vendor-supplied mitigation in KB5002655 and should evaluate that update against any conditional-formatting scenarios Microsoft flagged.

Users running Office 2016 Click-to-Run editions and other affected Excel versions—Excel 2019, 2021, 2024, and Excel Online—do not receive relief from KB5002655 and must rely on the Paste Special workaround or remove KB5002914 at the expense of losing numerous security patches.

IT teams must balance operational continuity against security exposure: the practical choices are to deploy Microsoft’s targeted MSI fix where applicable, instruct affected users to use Paste Special, or rollback KB5002914 with the clear understanding that doing so removes fixes for remote code execution and information disclosure vulnerabilities. The commands published in Microsoft’s advisory provide the path for rollback but also underline the patch-management trade-offs at play.

Microsoft’s immediate remediation addresses only a subset of affected customers. Until the company issues a permanent, broadly applicable fix, affected users will either tolerate reduced Excel functionality, follow manual paste workflows, or accept the security risk of uninstalling the September security update. The timeline for a comprehensive solution for Excel Online and Click-to-Run editions remains unreported in the vendor’s advisory.

Read the original report: https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-copy-and-paste-for-excel-2016-users/