Microsoft Secure Boot shim bypass
Analysis based on 12 articles · First reported Jul 14, 2026 · Last updated Jul 26, 2026
The vulnerability undermines trust in Secure Boot, a foundational PC security feature, potentially affecting enterprise purchasing decisions and increasing demand for firmware security solutions. Microsoft's delayed response may lead to regulatory scrutiny and reputational damage, while cybersecurity firms like ESET and runZero gain visibility.
ESET researchers discovered 11 old UEFI shim bootloaders signed by Microsoft that remained trusted despite known vulnerabilities, allowing attackers to bypass Secure Boot on Windows and Linux devices. Some shims dated back to 2013. Microsoft failed to revoke them for over a decade until June 2026 after ESET reported the issue to CERT. The vulnerability requires no sophisticated exploit; attackers only need a copy of an unrevoked shim. The incident has drawn criticism of the Secure Boot model's complexity and reliance on Microsoft as the root of trust.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard