Vulnerabilities · 60 days ago

Legacy Shim Revocations Leave Secure Boot Gaps

Secure Boot only holds here if every old Microsoft-signed shim has been revoked, and that inventory is incomplete. That means a machine can still accept a trusted first-stage loader that was never shipped with the PC, then hand control to an older second-stage loader that admits unsigned code.

ESET identified eleven Microsoft-signed shim versions at 0.9 or below that bypass UEFI Secure Boot. Microsoft revoked them on June 9, 2026, but the signing history is incomplete, so the remaining exposure is unknown; the risk reaches any UEFI system that trusts the Microsoft Corporation UEFI CA 2011, including systems that never installed the vulnerable shim themselves.

The broken assumption is simple: 'Secure Boot enabled' does not equal 'boot path protected' if a legacy shim is still reachable. That makes historical shim inventory and revocation coverage part of the control itself, not just patch hygiene.

CVE-2026-8863

NVD KEV

CVSS 7.8 HIGH: multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. EPSS 0.1% (1st percentile). Microsoft patch: 5094123.

Patch available KB5094123 Download →

Timeline

Sources

7 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-07-17

Editions

Related stories