← All stories
● Covered by 3 sources · 3 reportsMedium impact

Microsoft Revokes Vulnerable UEFI Shims Allowing Secure Boot Bypass

🔄 Updated 78d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 11 old UEFI shims signed by Microsoft are vulnerable.
  • Secure Boot bypass can occur on Windows and Linux systems.
  • Vulnerabilities existed due to expired certificate trust.
  • Shims were designed to aid Linux Secure Boot compatibility.
  • Microsoft revoked these vulnerable shims' signatures.

Security Flaw in UEFI Shims Exposed

Researchers at ESET have uncovered significant security vulnerabilities in 11 UEFI shim bootloaders signed by Microsoft. These outdated applications allowed attackers to bypass Secure Boot protections on both Windows and Linux systems.

The shims, which serve as lightweight bootloaders enabling Secure Boot compatibility for Linux distributions, were trusted due to expired Microsoft certificate authority protections.

Impact on Secure Boot Protections

The flaw threatened security by enabling the execution of untrusted and potentially malicious code during system boot. This issue stemmed from Microsoft's failure to revoke outdated shims even after vulnerabilities were identified.

Such vulnerabilities allowed attackers to deploy bootkits and other malware by circumventing the digitally signed firmware chain required during boot time.

Certifications and Remediation Efforts

The vulnerable shims, mainly from version 0.9 or earlier, remained signed and trusted until Microsoft's corrective actions. Microsoft has since revoked the vulnerable shim signatures as of the June 2026 Patch Tuesday, addressing these potential exploits.

Two CVEs have been assigned to this security flaw, CVE-2026-8863 and CVE-2026-10797, highlighting the criticality of the issue and prompting updates.

Wide-ranging Security Implications

This discovery affects not just Linux systems but also Windows machines, due to the cross-platform nature of the Secure Boot standard. This incident stresses the importance of regular updates and vigilance in digital certificate management for maintaining system integrity and security.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

ESET warns that several old UEFI shim bootloaders signed by Microsoft enable attackers to bypass Secure Boot protections. Microsoft has revoked the signatures of these vulnerable shims, which posed significant security risks by allowing untrusted code execution during the boot process.

ESET researchers discovered that Microsoft's Secure Boot can be bypassed using outdated shims, posing significant security risks for both Windows and Linux users. The flaw exists due to the continued trust in old firmware images, which remain unrevoked despite known vulnerabilities.

Researchers found 11 outdated Microsoft-signed UEFI applications that can be exploited to bypass Secure Boot on affected systems. This vulnerability can enable the execution of untrusted code and facilitate the deployment of UEFI bootkits.