Snapshot from Aug 24, 2026 at 07:00 UTC. For live data and tracking: View Live
Tech security vulnerability

Microsoft Secure Boot shim bypass

Analysis based on 12 articles · First reported Jul 14, 2026 · Last updated Jul 26, 2026

Sentiment
-30
Attention
4
Articles
12
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The vulnerability undermines trust in Secure Boot, a foundational PC security feature, potentially affecting enterprise purchasing decisions and increasing demand for firmware security solutions. Microsoft's delayed response may lead to regulatory scrutiny and reputational damage, while cybersecurity firms like ESET and runZero gain visibility.

cybersecurity software computer hardware

ESET researchers discovered 11 old UEFI shim bootloaders signed by Microsoft that remained trusted despite known vulnerabilities, allowing attackers to bypass Secure Boot on Windows and Linux devices. Some shims dated back to 2013. Microsoft failed to revoke them for over a decade until June 2026 after ESET reported the issue to CERT. The vulnerability requires no sophisticated exploit; attackers only need a copy of an unrevoked shim. The incident has drawn criticism of the Secure Boot model's complexity and reliance on Microsoft as the root of trust.

90 Microsoft failed to revoke
80 ESET discovered vulnerability
70 Microsoft revoked shims
60 ESET reported vulnerability Microsoft
30 H. D. Moore criticized Secure Boot
stock
Microsoft is the root of trust for Secure Boot; its failure to revoke vulnerable shims for over a decade has damaged its reputation and raised questions about its security oversight.
Importance 100.0 Sentiment -40.0
priv
ESET discovered and reported the vulnerability, enhancing its credibility in cybersecurity research.
Importance 80.0 Sentiment 30.0
govactor
CERT coordinated the disclosure and helped facilitate the revocation process.
Importance 50.0 Sentiment 10.0
stock
Oracle's shim allowed a binary vulnerable to CVE-2015-5381, highlighting security gaps in its boot components.
Importance 40.0 Sentiment -20.0
per
Martin Smolar is the ESET researcher who detailed the vulnerability and its implications.
Importance 40.0 Sentiment 10.0
oth
OpenSUSE was among the distributors with vulnerable shims; users must check for updates.
Importance 30.0 Sentiment -10.0
per
H. D. Moore criticized the Secure Boot model, calling it 'broken' and needing a reboot.
Importance 30.0 Sentiment 10.0
priv
runZero's CEO H. D. Moore commented on the incident, reinforcing the company's thought leadership in firmware security.
Importance 20.0 Sentiment 10.0
priv
PC-Doctor's shim was among the vulnerable ones, affecting its diagnostic software.
Importance 20.0 Sentiment -10.0
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.