Eleven Old Microsoft-Signed UEFI Shims Enable Bypass of Secure Boot on Linux Systems Still Trusting Microsoft Corporation UEFI CA 2011
Eleven legacy UEFI shim bootloaders, all signed by Microsoft and dating back to version 0.9 or earlier, can be exploited to bypass UEFI Secure Boot on systems whose firmware still trusts the Microsoft Corporation UEFI CA 2011 certificate. The vulnerability allows an attacker who can place one of these old but validly signed shims into the boot chain to execute arbitrary code before the operating system starts, effectively turning a trusted loader into a vector for pre-OS compromise.
The risk is comparable to a BYOVD (Bring Your Own Vulnerable Driver) attack but occurs at the firmware level. An attacker does not need the original software that shipped the shim; it is sufficient for the firmware to accept the signature and for the attacker to modify the EFI partition, disk, or boot media. Because execution happens before the OS loads, traditional endpoint detection and response telemetry often remains blind to the activity, making persistence via UEFI bootkits significantly easier.
The affected shims are linked to multiple distributions and third-party tools, including Red Hat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, openSUSE, baramundi Management Suite up to 2024R1, WipeDrive versions 8.0.0 through 8.1.3, PC Doctor Service Center, and Abitti 1. Two CVEs—CVE-2026-8863 and CVE-2026-10797—cover different portions of the problem.
Mitigation Strategy
Microsoft has already published revocation entries for the vulnerable shims in the DBX database. Once applied, firmware will refuse to execute the old binaries even though they carry a valid signature. However, simply revoking the hashes without preparation can prevent systems from booting if older components remain in the chain.
The recommended sequence is therefore:
- First update shim, GRUB, and all other boot components to current versions that include SBAT (Shim Boot Application Table) protections.
- Only after these updates are verified, deploy the DBX revocations.
- Test the changes on a representative subset of machines before broad rollout.
- Inventory rescue media and maintenance USB drives, because any that still contain old shims will become unusable after revocation.
Administrators can verify the final state of Secure Boot variables using tools such as Check UEFISecureBootVariables on Windows or uefi dbx audit on Linux. It is also important to note that the scheduled expiration of the Microsoft UEFI CA 2011 certificate on 27 June 2026 does not automatically invalidate previously signed binaries; only an explicit DBX entry removes trust.
More information is available from The Hacker News, CERT Coordination Center (VU#616257), NIST NVD (CVE-2026-8863), and Help Net Security.
Related articles
NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU
Neoflex has released NEOMSA APIM 4.6.0 with a primary focus on strengthening the security of the platform's supply chain. The team generated an SBOM in CycloneDX format, scanned components and dependencies using Grype, and cross-referenced findings against the FSTEC BDU database. This process reduced total registered vulnerabilities from 57 to 7, completely removing all 10 Critical and 24 High issues. The platform now meets the formal Security Gate criterion requiring zero Critical or High vulnerabilities from the FSTEC database in the final build. Remaining Medium findings are documented and tracked for future updates. The release provides customers with a verified, transparent component inventory that simplifies compliance and integration reviews.
Cisco Publishes 12 Security Advisories Fixing Critical Flaws in Catalyst SD-WAN and IOS XE
Cisco Systems released 12 new security advisories on August 5, 2026, disclosing a total of 23 vulnerabilities across multiple products. Two advisories covering Cisco Catalyst SD-WAN Software and Cisco IOS XE Software received the highest Critical severity rating. The SD-WAN advisory addresses five issues, including CVE-2026-20303, CVE-2026-20304, and CVE-2026-20310, each scoring 9.9 on CVSSv3.1. The IOS XE advisory details seven vulnerabilities, with CVE-2026-20272 rated 9.8 and CVE-2026-20267 rated 9.0. Additional advisories cover flaws in Integrated Management Controller, RoomOS, and Terminal Services Agent. Organizations are urged to apply the hardening releases immediately to mitigate remote exploitation risks.
Head Mare Hackers Exploit TrueConf Servers to Distribute PhantomCore and PhantomGraph Backdoors
Russian organizations have been targeted in a new campaign by the Head Mare group, which compromises unpatched TrueConf servers to deliver backdoors. Attackers chain vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with maximum privileges on affected servers. They then replace a server file with a web shell to explore the victim's infrastructure, access the TrueConf database, and substitute the client installer. Victims are tricked via social engineering into downloading the malicious client during video conferences without any suspicious emails. The campaign affects TrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. Kaspersky researchers recommend immediate updates to patched versions 5.3.9, 5.4.9, and 5.5.5 released on 18 June 2026. The threat extends beyond direct TrueConf users, as any employee invited to a compromised server can inadvertently install the backdoor.
Zapscape Flaw in KVM Breaks Nested Virtualization Isolation Allowing L1 Guest Root Code Execution on Linux Host
The Zapscape vulnerability (CVE-2026-64561) affects KVM/x86 in the Linux kernel and enables an attacker with kernel privileges inside an L1 virtual machine to escape to the host and execute code as root. The flaw occurs in the shadow MMU when handling page faults for nested guests, specifically due to an incorrect order of stale root condition checks that leads to a use-after-free condition. This weakens the isolation between the host and L1 guests precisely when nested virtualization is enabled for potentially untrusted tenants. A public proof-of-concept demonstrates the escape by creating a file named /Zapscape owned by root on the host. The issue impacts Linux kernels starting from version 5.9, with fixes already merged into stable branches including 6.6.148, 6.12.101, 6.18.42, 7.1.6 and 7.2 rc5. On Intel systems the attack requires EPT page walk lengths 4 and 5 to be exposed to the L1 guest, while no equivalent condition is documented for AMD. Organizations are advised to apply patches promptly or disable nested virtualization for untrusted workloads.