ESET Reports 11 Microsoft-Signed UEFI Shims Enable Secure Boot Bypass
This digest was compiled by AI from multiple sources — links to the originals are below.

ESET researchers have discovered 11 Microsoft-signed UEFI shim bootloaders that enable attackers to bypass Secure Boot and load untrusted code at startup. Microsoft revoked the vulnerable binaries in its June 9, 2026 Patch Tuesday update. The shims are part of legitimate Linux boot loaders but carry decade-old flaws in their trusted GRUB 2 components.
Decade-Old Vulnerabilities
The 11 shim bootloaders, all version 0.9 or earlier, were signed under Microsoft’s UEFI CA 2011 third-party certificate, which is trusted by any UEFI system. They rely on outdated GRUB 2 binaries with signing timestamps from 2013 to 2025, many carrying known flaws. ESET demonstrated an attack using the Oracle Linux shim, which trusts a GRUB 2 version vulnerable to a 2015 bug that allows unsigned code execution via crafted multiboot modules. No memory corruption is needed; an attacker simply copies an unsigned kernel image alongside the old shim and GRUB 2.
Bypassing Modern Defenses
Older shims lack enforcement of the Machine Owner Key (MOK) denylist, added in version 0.9, and ignore Secure Boot Advanced Targeting (SBAT) policies introduced in shim 15.3, rendering organization-level revocations ineffective. ESET warns that unknown numbers of vulnerable shims remain in circulation because submissions were not cataloged transparently before 2017. Two CVE identifiers, CVE-2026-8863 and CVE-2026-10797, cover the issue. Microsoft revoked the binaries in its June 9, 2026 dbx update, which Windows machines receive automatically.
What's Next
Linux users must manually pull the revocation through the Linux Vendor Firmware Service. It remains unclear how many systems still trust the revoked shims and whether threat actors have already exploited them in the wild.
1 source
ESET Reports 11 Microsoft-Signed UEFI Shims Enable Secure Boot Bypass






