Microsoft-signed UEFI bootloaders vulnerable to Secure Boot bypass
Microsoft has released security updates to address a Secure Boot bypass vulnerability affecting multiple Microsoft-signed UEFI shim bootloaders used by Linux distributions, recovery tools, and enterprise software. The flaw, tracked as CVE-2026-8863, could allow attackers to execute malicious code before the operating system loads. The issue was discovered by Martin Smolar of ESET and disclosed … The post Microsoft-signed UEFI bootloaders vulnerable to Secure Boot bypass appeared first on CyberInsider.
A Secure Boot bypass vulnerability (CVE-2026-8863) in Microsoft-signed UEFI shim bootloaders allows attackers to execute arbitrary code before the operating system loads, potentially leading to malware installation and evasion of endpoint security products.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at Cyber Insider.
