← Back to Feed
Forgotten UEFI shims undermining Secure Boot
July 14, 2026 · WeLiveSecurity · Severity: HIGH
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft, allowing attackers to bypass UEFI Secure Boot using decade-old vulnerabilities.
Key Takeaways
- ESET found 11 vulnerable UEFI shims signed by Microsoft bypassing Secure Boot.
- Decade-old vulnerabilities in bootloaders undermine UEFI Secure Boot protections.
- Attackers can exploit forgotten shims to compromise system boot security.