Eleven Old Microsoft-Signed UEFI Shims Enable Bypass of Secure Boot on Linux Systems Still Trusting Microsoft Corporation UEFI CA 2011
Eleven legacy UEFI shim bootloaders, all signed by Microsoft and dating back to version 0.9 or earlier, can be exploited to bypass UEFI Secure Boot on systems whose firmware still trusts the Microsoft Corporation UEFI CA 2011 certificate. The vulnerability allows an attacker who can place one of these old but validly signed shims into the boot chain to execute arbitrary code before the operating system starts, effectively turning a trusted loader into a vector for pre-OS compromise.
The risk is comparable to a BYOVD (Bring Your Own Vulnerable Driver) attack but occurs at the firmware level. An attacker does not need the original software that shipped the shim; it is sufficient for the firmware to accept the signature and for the attacker to modify the EFI partition, disk, or boot media. Because execution happens before the OS loads, traditional endpoint detection and response telemetry often remains blind to the activity, making persistence via UEFI bootkits significantly easier.
The affected shims are linked to multiple distributions and third-party tools, including Red Hat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, openSUSE, baramundi Management Suite up to 2024R1, WipeDrive versions 8.0.0 through 8.1.3, PC Doctor Service Center, and Abitti 1. Two CVEs—CVE-2026-8863 and CVE-2026-10797—cover different portions of the problem.
Mitigation Strategy
Microsoft has already published revocation entries for the vulnerable shims in the DBX database. Once applied, firmware will refuse to execute the old binaries even though they carry a valid signature. However, simply revoking the hashes without preparation can prevent systems from booting if older components remain in the chain.
The recommended sequence is therefore:
- First update shim, GRUB, and all other boot components to current versions that include SBAT (Shim Boot Application Table) protections.
- Only after these updates are verified, deploy the DBX revocations.
- Test the changes on a representative subset of machines before broad rollout.
- Inventory rescue media and maintenance USB drives, because any that still contain old shims will become unusable after revocation.
Administrators can verify the final state of Secure Boot variables using tools such as Check UEFISecureBootVariables on Windows or uefi dbx audit on Linux. It is also important to note that the scheduled expiration of the Microsoft UEFI CA 2011 certificate on 27 June 2026 does not automatically invalidate previously signed binaries; only an explicit DBX entry removes trust.
More information is available from The Hacker News, CERT Coordination Center (VU#616257), NIST NVD (CVE-2026-8863), and Help Net Security.
Related articles
Cisco ISE Affected by 42 Vulnerabilities Including Multiple Critical Flaws with Confirmed Exploitation
Cisco Identity Services Engine (ISE) has been found to contain 42 vulnerabilities across 15 security advisories released by Cisco Systems on September 16, 2026. Six advisories received the highest Critical rating, covering 21 individual vulnerabilities, while three were rated High and six Medium. One standout issue, CVE-2026-76460, allows attackers to bypass authentication on the management API via crafted HTTP requests and execute commands with root privileges. The flaw also impacts the Cisco ISE Passive Identity Connector (ISE-PIC). Cisco has urged immediate application of updates as some vulnerabilities are already being exploited in the wild. The product provides core network authentication and access control functions for enterprise environments.
CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog, Including Cisco ISE and Acronis Backup Flaws
The US Cybersecurity and Infrastructure Security Agency has added three vulnerabilities with confirmed in-the-wild exploitation to its Known Exploited Vulnerabilities catalog. The flaws affect Cisco Identity Services Engine, its Passive Identity Connector, and Acronis Backup plugins for cPanel and Plesk. All three entries carry a remediation deadline of September 19, 2026. The Cisco issue stems from insufficient authentication controls on an API endpoint that lets remote attackers bypass the web-based management interface. The Acronis vulnerability arises from overly permissive default settings in server-management plugins, enabling privilege escalation. Federal agencies have been directed to investigate potential compromises and apply mitigations without delay.
R-Vision VM 6.6 Adds Container Scanning, Web Application Audits and Mobile Scanner for Isolated Networks
R-Vision has released version 6.6 of its vulnerability management platform, expanding detection capabilities to web applications, Docker and Kubernetes container environments, and previously unreachable isolated network segments. The new web audit feature inventories resources and identifies associated vulnerabilities, although the company describes the current functionality as basic and not intended to replace dedicated DAST solutions. Container auditing now covers both Docker and Kubernetes, including runtime analysis, with findings presented directly in the host card within the central console. The most notable addition is a mobile scanner that runs on a laptop without requiring dedicated servers, allowing security specialists to audit air-gapped or remote sites and later upload results to the main R-Vision VM instance. The mobile component supports White Box, Black Box, Compliance and web-audit modes, performs full inventory, and is designed to scan up to 2000 hosts. Additional improvements include expanded inventory for ESXi, vCenter and network equipment, updated compliance checks, enhanced dashboards, automation policies and data export options, plus the ability to update agents directly from the interface.
BloodHound, smbmap and enum4linux-ng: Essential Tools for Starting Active Directory Penetration Testing
Active Directory remains the primary target in most internal penetration tests, regardless of how an attacker first gains network access. The article outlines a practical reconnaissance workflow that begins with identifying the domain name and domain controllers through port scanning for ports 88 and 389. Tools such as enum4linux-ng enable initial data collection without credentials by leveraging null sessions, while smbmap reveals readable and writable SMB shares that often contain SSH keys, certificates, and plaintext passwords. BloodHound, paired with collectors like SharpHound, maps relationships between users, groups, and computers to reveal attack paths toward Domain Admins. The piece stresses understanding Kerberos and NTLM protocols to apply techniques such as Kerberoasting, AS-REP Roasting, and pass-the-hash effectively rather than running commands blindly. It also covers quieter alternatives to noisy tools and provides a concise checklist for beginners, along with references to the Red September CyberED course on Active Directory attacks.