Researchers at ESET have uncovered significant security vulnerabilities in 11 UEFI shim bootloaders signed by Microsoft. These outdated applications allowed attackers to bypass Secure Boot protections on both Windows and Linux systems.
The shims, which serve as lightweight bootloaders enabling Secure Boot compatibility for Linux distributions, were trusted due to expired Microsoft certificate authority protections.
The flaw threatened security by enabling the execution of untrusted and potentially malicious code during system boot. This issue stemmed from Microsoft's failure to revoke outdated shims even after vulnerabilities were identified.
Such vulnerabilities allowed attackers to deploy bootkits and other malware by circumventing the digitally signed firmware chain required during boot time.
The vulnerable shims, mainly from version 0.9 or earlier, remained signed and trusted until Microsoft's corrective actions. Microsoft has since revoked the vulnerable shim signatures as of the June 2026 Patch Tuesday, addressing these potential exploits.
Two CVEs have been assigned to this security flaw, CVE-2026-8863 and CVE-2026-10797, highlighting the criticality of the issue and prompting updates.
This discovery affects not just Linux systems but also Windows machines, due to the cross-platform nature of the Secure Boot standard. This incident stresses the importance of regular updates and vigilance in digital certificate management for maintaining system integrity and security.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
ESET warns that several old UEFI shim bootloaders signed by Microsoft enable attackers to bypass Secure Boot protections. Microsoft has revoked the signatures of these vulnerable shims, which posed significant security risks by allowing untrusted code execution during the boot process.
ESET researchers discovered that Microsoft's Secure Boot can be bypassed using outdated shims, posing significant security risks for both Windows and Linux users. The flaw exists due to the continued trust in old firmware images, which remain unrevoked despite known vulnerabilities.
Researchers found 11 outdated Microsoft-signed UEFI applications that can be exploited to bypass Secure Boot on affected systems. This vulnerability can enable the execution of untrusted code and facilitate the deployment of UEFI bootkits.