← Back to Feed

Forgotten UEFI shims undermining Secure Boot

July 14, 2026 · WeLiveSecurity · Severity: HIGH

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft, allowing attackers to bypass UEFI Secure Boot using decade-old vulnerabilities.

Key Takeaways

  • ESET found 11 vulnerable UEFI shims signed by Microsoft bypassing Secure Boot.
  • Decade-old vulnerabilities in bootloaders undermine UEFI Secure Boot protections.
  • Attackers can exploit forgotten shims to compromise system boot security.
☕ Buy a Coffee