VU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass

Date Jun 9, 2026
Type Coordinated disclosure
Signal Patch review
Vendor / Product UEFI · applications and drivers must be cryptographically signed and verified
Patch review

Summary

Overview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Database (DBX). Once the DBX update is applied, these bootloaders will no longer be trusted for execution during the boot process. An attacker could exploit these vulnerable shim bootloaders using a Bring Your Own Vulnerable Driver (BYOVD)-style technique to execute arbitrary code during the early boot phase, prior to operating system initialization, thereby bypassing Secure Boot protections. Description The Unified Extensible Firmware Interface (UEFI) standard defines the modern firmware architecture used to initialize hardware and transfer control to the operating... Related CVEs: CVE-2026-10797, CVE-2026-8863.

Why it matters

CERT/CC notes often cover coordinated disclosures, multi-vendor exposure, infrastructure risk, or cases where remediation guidance is still developing.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for applications and drivers must be cryptographically signed and verified where available.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.