Eleven Old Microsoft-Signed UEFI Shims Enable Bypass of Secure Boot on Linux Systems Still Trusting Microsoft Corporation UEFI CA 2011
Eleven legacy UEFI shim bootloaders, all signed by Microsoft and dating back to version 0.9 or earlier, can be exploited to bypass UEFI Secure Boot on systems whose firmware still trusts the Microsoft Corporation UEFI CA 2011 certificate. The vulnerability allows an attacker who can place one of these old but validly signed shims into the boot chain to execute arbitrary code before the operating system starts, effectively turning a trusted loader into a vector for pre-OS compromise.
The risk is comparable to a BYOVD (Bring Your Own Vulnerable Driver) attack but occurs at the firmware level. An attacker does not need the original software that shipped the shim; it is sufficient for the firmware to accept the signature and for the attacker to modify the EFI partition, disk, or boot media. Because execution happens before the OS loads, traditional endpoint detection and response telemetry often remains blind to the activity, making persistence via UEFI bootkits significantly easier.
The affected shims are linked to multiple distributions and third-party tools, including Red Hat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, openSUSE, baramundi Management Suite up to 2024R1, WipeDrive versions 8.0.0 through 8.1.3, PC Doctor Service Center, and Abitti 1. Two CVEs—CVE-2026-8863 and CVE-2026-10797—cover different portions of the problem.
Mitigation Strategy
Microsoft has already published revocation entries for the vulnerable shims in the DBX database. Once applied, firmware will refuse to execute the old binaries even though they carry a valid signature. However, simply revoking the hashes without preparation can prevent systems from booting if older components remain in the chain.
The recommended sequence is therefore:
- First update shim, GRUB, and all other boot components to current versions that include SBAT (Shim Boot Application Table) protections.
- Only after these updates are verified, deploy the DBX revocations.
- Test the changes on a representative subset of machines before broad rollout.
- Inventory rescue media and maintenance USB drives, because any that still contain old shims will become unusable after revocation.
Administrators can verify the final state of Secure Boot variables using tools such as Check UEFISecureBootVariables on Windows or uefi dbx audit on Linux. It is also important to note that the scheduled expiration of the Microsoft UEFI CA 2011 certificate on 27 June 2026 does not automatically invalidate previously signed binaries; only an explicit DBX entry removes trust.
More information is available from The Hacker News, CERT Coordination Center (VU#616257), NIST NVD (CVE-2026-8863), and Help Net Security.
Related articles
ServiceNow Patches Multiple Critical Vulnerabilities in Now Platform and AI Platform
ServiceNow disclosed several critical vulnerabilities affecting the Now Platform and ServiceNow AI Platform on August 27. The issues include unauthenticated code injection via the GraphQL Composite Data API, improper access controls during system image uploads, and SQL injection flaws that allow arbitrary database queries. Four CVEs were published: CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. Exploitation of CVE-2026-18885 could permit remote code execution and data manipulation without authentication under certain conditions. CVE-2026-18886 enables unauthorized data creation, modification, and privilege escalation, while CVE-2026-74820 allows direct SQL execution against the underlying database. ServiceNow has released updated versions to address the flaws.
CISA Adds Linux Kernel Frag Gap Flaw and Two Other Exploited Vulnerabilities to KEV Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 27, 2026. One of the entries is CVE-2026-53362, a high-severity privilege escalation issue in the Linux kernel also known as Frag Gap. The flaw stems from an out-of-bounds write when generating IPv6 packets, allowing a low-privileged user to obtain root access. The Linux Kernel Organization assigned it a CVSS v3.1 base score of 7.8 and rated it High severity, with public exploit code already available. Federal agencies must remediate CVE-2026-53362 and CVE-2023-49105 by the August 30 deadline. The advisory underscores ongoing exploitation of these issues in the wild.
CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws
On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling confirmed active exploitation and requiring immediate remediation priority. The batch includes a recent memory corruption issue in Citrix NetScaler ADC and NetScaler Gateway tracked as CVE-2026-8452, along with five older flaws affecting Microsoft SQL Server, the Linux kernel, Ajax.NET Professional, Red Hat libuser, and Red Hat ABRT. Citrix released patches for the NetScaler vulnerability on June 30, 2026, while CISA set an August 29, 2026 deadline for federal agencies. Real-world attacks have already deployed web shells and performed reconnaissance after successful exploitation of the Citrix appliance. The remaining CVEs enable remote code execution, local privilege escalation, and denial-of-service conditions across widely deployed enterprise technologies.
Next.js Patches Two Critical RCE Vulnerabilities in Versions 15.5.24 and 16.3.3
Next.js has released security updates to address two critical vulnerabilities that could allow unauthenticated remote code execution. The fixes are available in versions 15.5.24 and 16.3.3. The first issue, tracked as CVE-2026-75604 with a CVSS score of 9.0, affects applications hosted on Windows servers using Pages Router or App Router without Cache Components and stems from a path traversal flaw. The second vulnerability impacts the Image Optimization API when processing malicious AVIF files, enabling code execution through crafted image inputs. Both flaws affect a wide range of versions from 10.0.0 and 13.4 onward. Administrators are advised to update immediately, rebuild containers, and verify production environments run the patched releases, especially on Windows systems and those handling user-uploaded images.