Notebookcheck
Secure Boot Certificate Expiration Threatens Windows Security Posture
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft's Secure Boot certificates from 2011 are set to expire between June 24-27, 2026, affecting devices that haven't received the 2023 replacement certificates. While devices will continue to boot, they will lose the ability to receive future boot-level security updates, leaving them vulnerable to threats like the BlackLotus bootkit. The June 9 Patch Tuesday is the last chance for organizations to update their systems before the expiration. IT teams are advised to check certificate status using PowerShell commands to ensure compliance. Delays in updating could lead to significant security gaps, especially for enterprise environments. The expiration affects Windows 11 and Windows Server systems, particularly those that did not receive the 2023 certificates during the rollout. The situation is compounded by the recent discovery of CVE-2026-41089, which is actively exploited.
Key Points: • Secure Boot certificates from 2011 expire between June 24-27, 2026, risking security. • Devices without updated certificates will lose future boot-level security protections. • June 9 Patch Tuesday is the last chance for updates before the expiration deadline.