Microsoft-signed old Linux UEFI shim bootloaders could let attackers bypass Secure Boot on many PCs and servers, even if they do not run Linux. ESET says 11 legacy shims, mainly version 0.9 and earlier, remained trusted under Microsoft's third-party UEFI certificate and could be used to load vulnerable second-stage bootloaders or attacker-supplied components during startup. The issues are tracked as CVE-2026-8863 and CVE-2026-10797, and Microsoft revoked the affected binaries in the June 2026 Patch Tuesday UEFI DBX (Forbidden Signature Database) update.
Why it matters: This weakens a core startup security control that many organizations rely on to stop bootkits and other low-level malware. Enterprises and cloud operators should update trusted boot components first and then deploy the DBX revocations, because doing it in the wrong order can break system boot.
Ionut Arghire
2026.07.16
100% relevant
This article establishes a distinct vulnerability-and-revocation story centered on legacy Microsoft-signed UEFI shims, the assigned CVEs, and June 2026 Secure Boot trust-chain changes.
← Back to all stories