Cybersecurity researchers at ESET have discovered 11 old, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot protections on most systems using the modern firmware standard. The vulnerable shims, mainly from version 0.9 and earlier of the open-source shim project, allow attackers to execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits like Bootkitty, HybridPetya, or BlackLotus even when Secure Boot is enabled.
The shim bootloaders expose any UEFI-based machine that trusts Microsoft’s ‘Microsoft Corporation UEFI CA 2011’ third-party UEFI certificate authority certificate, regardless of the installed operating system. The certificate expired on June 27, 2026, but its expiration has no bearing on Secure Boot verification as long as the bootloaders signed with the expired certificate are not explicitly revoked by hash.
An attacker with administrative privileges or the ability to modify the boot process could replace a victim’s up-to-date shim with an older Microsoft-signed UEFI shim, bypassing MOK denylist enforcement and Secure Boot Advanced Targeting (SBAT) mechanisms. This allows arbitrary code execution before the operating system initializes, sidestepping detection by built-in security controls and endpoint detection and response (EDR) solutions.
The issues are tracked under CVE-2026-8863 and CVE-2026-10797. Microsoft revoked the affected bootloaders as part of its June 2026 Patch Tuesday update following responsible disclosure in February 2026. The CERT Coordination Center noted that vendor-specific bootloaders had not been updated to address vulnerabilities in the upstream project, creating a long-term supply chain exposure.
CVEs: CVE-2026-8863, CVE-2026-10797
Malware: Bootkitty, HybridPetya, BlackLotus
Companies: ESET, Microsoft, Red Hat, Oracle, SUSE, Spyrus, Baramundi, WhiteCanyon, Blancco, PC-Doctor, NTC IT ROSA, CERT Coordination Center
Products: UEFI shim, GRUB 2, Red Hat Enterprise Linux, CentOS, Oracle Linux, OpenSUSE, baramundi Management Suite, WipeDrive, PC Doctor Service Center, ROSA Linux, Abitti
Original source: thehackernews.com