Outdated Microsoft-signed UEFI shims bypass Secure Boot
ESET warns 11 older Microsoft‑signed UEFI shims could bypass Secure Boot on systems trusting Microsoft’s UEFI CA 2011. Microsoft revoked the shims on June 2026 Patch Tuesday.
ESET reported that 11 outdated UEFI shim bootloaders signed by Microsoft could be used to bypass Secure Boot on any machine that trusts the Microsoft Corporation UEFI CA 2011 certificate. Microsoft revoked the affected signatures and added the entries to the UEFI DBX on the June 2026 Patch Tuesday after the firm alerted CERT/CC in February 2026.
UEFI shims are small programs that let a motherboard’s firmware load an operating system component, commonly used by Linux distributions to boot with Secure Boot enabled. Vendors and distributions often rely on Microsoft signing so they do not have to install individual keys into a board’s NVRAM. ESET found most of the vulnerable shims were version 0.9 or earlier and remained both signed and trusted.
Two vulnerabilities were assigned to the issue: CVE-2026-8863 and CVE-2026-10797. ESET noted that the signing and compilation timestamps of the trusted applications span from 2013 to 2025, and many of the binaries predate formal shim vetting introduced in 2017. The firm pointed to known flaws in related components, such as the BootHole vulnerability in GRUB2, as examples of risks that can persist when old signed boot components remain in use.
Microsoft’s revocation placed the affected files in the DBX, the firmware forbidden signature database. CERT/CC advised administrators to update trusted boot applications and certificates before applying DBX revocations. “In practice, this means updating trusted boot applications and certificates first, followed by deployment of the revocation list. Failure to follow this order may cause systems to reject newly updated boot components,” the advisory said, and urged large-scale operators to validate and deploy fixes carefully.
ESET described two exploitation paths: attackers can reuse old, trusted shims already present on devices, or they can introduce a vulnerable shim that is signed under Microsoft’s third-party UEFI certificate if that certificate is enrolled on a system. Because many of the affected binaries carry long-spanning timestamps, the trusted second-stage bootloaders increase the window for attackers to run untrusted code during boot and to install persistent bootkits even when Secure Boot is enabled.
ESET and CERT/CC timelines and the DBX entries show the issue was addressed through certificate revocation in June 2026. Organizations and administrators tracking firmware and boot components can compare installed shim versions and firmware signature databases against the revoked entries to identify impacted systems and follow the published update sequence to avoid startup failures.








