Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass

Security researchers at ESET have identified 11 Microsoft-signed UEFI shim bootloaders that contain vulnerabilities allowing attackers to bypass Secure Boot. These flaws could enable the installation of persistent bootkits on a wide range of systems.
Why it matters
This vulnerability poses a significant security risk as it allows malicious code to execute before the operating system loads, potentially compromising entire systems.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade, according to new findings from ESET.
ESET researchers reported the shims to the CERT Coordination Center (CERT/CC) in February 2026. All are versions 0.9 or below and were signed under Microsoft's Microsoft Corporation UEFI CA 2011 third-party certificate, meaning any UEFI system that trusts that certificate will accept them regardless of the installed operating system.
Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits such as Bootkitty , HybridPetya and BlackLotus , even with Secure Boot switched on.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in