CVE-2026-8863
CVSS 7.8 HIGH: multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. EPSS 0.1% (1st percentile). Microsoft patch: 5094123.
Patch available KB5094123 Download →
Vulnerabilities · 60 days ago
Secure Boot only holds here if every old Microsoft-signed shim has been revoked, and that inventory is incomplete. That means a machine can still accept a trusted first-stage loader that was never shipped with the PC, then hand control to an older second-stage loader that admits unsigned code.
ESET identified eleven Microsoft-signed shim versions at 0.9 or below that bypass UEFI Secure Boot. Microsoft revoked them on June 9, 2026, but the signing history is incomplete, so the remaining exposure is unknown; the risk reaches any UEFI system that trusts the Microsoft Corporation UEFI CA 2011, including systems that never installed the vulnerable shim themselves.
The broken assumption is simple: 'Secure Boot enabled' does not equal 'boot path protected' if a legacy shim is still reachable. That makes historical shim inventory and revocation coverage part of the control itself, not just patch hygiene.
CVSS 7.8 HIGH: multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. EPSS 0.1% (1st percentile). Microsoft patch: 5094123.
Patch available KB5094123 Download →
7 sources covering this story
Old UEFI Shims Expose Systems to Secure Boot Bypass
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
Forgotten Bootloaders Expose Secure Boot Blind Spot
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Eleven old Microsoft-signed UEFI shims could let admin-level attackers bypass Secure Boot and run code before the operating system loads
No one knows how many old shims can still bypass UEFI Secure Boot - Help Net Security
Eleven forgotten Microsoft-signed shims enabled a UEFI Secure Boot bypass on nearly any PC.
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
Part of the PlainSec briefing for 2026-07-17