Secure Boot Bypassed for Over a Decade Through Unrevoked Vulnerable Shim Bootloaders, ESET Finds
Secure Boot, one of the primary security mechanisms protecting Windows and Linux systems from early-stage malware, could be bypassed for nearly its entire existence, researchers at ESET have revealed. The flaw remained undetected for more than ten years because Microsoft continued to trust outdated shim bootloader images that contained known vulnerabilities.
The shim components were originally created to extend Secure Boot support to Linux distributions and pre-OS utilities. Microsoft signed these files with its own certificate, allowing UEFI firmware to execute them during the boot process. ESET identified 11 vulnerable shim images; the oldest known sample appeared in 2013, only one year after Secure Boot was introduced.
Although the vulnerabilities in these components had been publicly known for years, Microsoft never added the corresponding hashes or certificates to the UEFI revocation database (dbx). As a result, systems continued to trust the old files, enabling attackers to break the signature verification chain and install persistent bootkits.
The attack required no new exploits. An adversary only needed a copy of one of the still-valid legacy shim files and basic knowledge of the UEFI boot process. Once executed, the compromised shim could disable subsequent signature checks and load malicious code before the operating system itself started.
Because UEFI firmware does not bind a Microsoft-signed shim to any particular operating system, the same vulnerable images could be used against both Linux and Windows machines. After bypassing Secure Boot, attackers could deploy bootkits such as LoJax, MosaicRegressor, CosmicStrand, or BlackLotus, some of which have been linked to nation-state actors.
The affected files were listed by CERT and included shims from Red Hat, openSUSE, Oracle, and third-party vendors such as Finnish company PC-Doctor, which was used in national examination systems. Several of the images predated modern revocation mechanisms like SBAT (Secure Boot Advanced Targeting) and SVN (Security Version Number), and some failed to honor Machine Owner Key deny lists.
Microsoft finally revoked the 11 vulnerable shims in its June security updates after receiving the report from ESET. The company is responsible for maintaining the central trust store for the UEFI ecosystem, yet the incident demonstrates how difficult it remains to track and revoke thousands of signed boot components over time.
Windows 11 Secured-core devices were likely protected by default thanks to additional hardware-backed policies, but general Windows and Linux users are advised to verify that their firmware has received the updated revocation lists via the Linux Vendor Firmware Service or the uefi-dbx-audit script.
Related articles
Critical Stack Buffer Overflow in TP-Link TL-WR940N Enables Remote Code Execution
A high-severity vulnerability tracked as CVE-2026-12935 with a CVSS score of 8.7 affects the TP-Link TL-WR940N router on hardware version V6. The flaw resides in the RTSP connection tracking module responsible for managing audio and video streaming sessions over the network. It is caused by a stack-based buffer overflow that allows oversized data to corrupt kernel memory, potentially leading to device crashes or full remote code execution. No administrative credentials are required for exploitation, though the attack depends on an RTSP connection initiated by a device already present on the local network. Successful compromise grants attackers the ability to alter router settings, modify DNS servers, intercept traffic, redirect users to malicious sites, and pivot to other connected devices. Users are advised to verify the hardware revision on the device label and apply the region-specific firmware update released by TP-Link.
N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577
N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.
Adobe Releases Emergency Update for Campaign Classic Fixing Multiple Critical Vulnerabilities
Adobe has issued an urgent security update for Adobe Campaign Classic to address seven critical vulnerabilities, including several with a maximum CVSSv3.1 base score of 10.0. The flaws affect on-premises deployments on Windows and Linux as well as the on-premises components of hybrid setups. Notably, the newly released fixes also impact the previous emergency update from July 29, version 7.4.3 build 9398, requiring users to apply the latest patch immediately. Among the most severe issues are a server-side request forgery vulnerability tracked as CVE-2026-48331, an input handling flaw in the template engine identified as CVE-2026-48323, and an SQL injection vulnerability labeled CVE-2026-48330. Adobe published the corresponding security advisory on August 3, 2026, urging rapid remediation despite the short interval since the prior update.
Dark Patterns in Vulnerability Management: How Metrics Undermine Real Security
Vulnerability management programs often fail not due to lack of scanners but because of poorly chosen metrics that prioritize reporting over actual risk reduction. Teams focus on closing easy vulnerabilities, meeting CVSS-based deadlines, and improving dashboard numbers while attackers exploit the shortest path to critical assets. The article examines five common traps including total vulnerability counts, context-free SLAs, closure rate targets, static dashboards, and claims of no critical findings. It argues that these metrics create a false sense of security and distort team behavior according to Goodhart's Law. Instead, organizations should adopt attack path metrics, exposure management approaches such as CTEM, and measurements that track real reduction in attacker reachability. The piece highlights MaxPatrol Carbon as an example of tools that model attacker paths rather than isolated CVEs.