Skip to content
Vulnerable UEFI shims allow attackers to bypass Secure Boot protections

Vulnerable UEFI shims allow attackers to bypass Secure Boot protections

Feeds.4Sysops •IT News • July 14, 2026

Researchers have identified at least eleven vulnerable UEFI shim bootloaders that allow attackers to bypass Secure Boot on any system trusting the Microsoft third-party certificate authority. These shims, primarily version 0.9 or older, act as a bridge between firmware and the operating system but contain decade-old flaws that can be exploited to execute unsigned code. Because attackers can simply bring their own copy of a trusted but vulnerable binary to a target machine, the protection is undermined regardless of the installed operating system. Source

Extracted Entities

Platforms (1)