CVE-2026-8863 Details
Description
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
A vulnerability exists in Microsoft-signed UEFI shim bootloaders, primarily in versions through 0.9, allowing for a Secure Boot bypass. This issue enables an attacker with administrative privileges or the ability to alter the boot process to execute arbitrary code before the operating system loads. The vulnerability arises because certain bootloaders were not updated after known security issues, leaving them signed and trusted by Secure Boot systems. Exploitation can lead to a persistent compromise, allowing the execution of unsigned or malicious kernel components that survive reboots and, in some cases, operating system reinstallation.
Users should apply the latest software and bootloader updates provided by their hardware or software vendor. After updating, ensure that any vulnerable shim bootloaders are replaced with versions that include the latest security fixes and Secure Boot Advanced Targeting (SBAT) protections. Additionally, apply the latest Microsoft UEFI Forbidden Signature Database (DBX) update to revoke the trust of the vulnerable bootloaders during the Secure Boot process. For enterprise environments, validate and test these updates before wide deployment to ensure systems remain bootable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/616257 | CVE | AdvisoryBundleRemedy |
| https://kb.cert.org/vuls/id/616257 | [email protected] | AdvisoryBundleRemedy |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Microsoft UEFI Shim | <= 0.9 |
CPE
Remediation
| |
| Spyrus WTGCreator | All versions |
CPE
Remediation
| |
| RedHat Enterprise Linux | All versions |
CPE
Remediation
| |
| RedHat CentOS | All versions |
CPE
Remediation
| |
| baramundi Management Suite | All versions |
CPE
Remediation
| |
| WhiteCanyon WipeDrive | All versions |
CPE
Remediation
| |
| Blancco WipeDrive | All versions |
CPE
Remediation
| |
| Finland's Matriculation Examination Board Abitti | All versions |
CPE
Remediation
| |
| NTC IT ROSA Linux | All versions |
CPE
Remediation
| |
| OracleLinux | All versions |
CPE
Remediation
| |
| PC Doctor Service Center | All versions |
CPE
Remediation
| |
| OpenSuse Shim | All versions |
CPE
Remediation
| |
| Microsoft Windows 11 | All versions |
CPE
Remediation
| |
| Microsoft Windows Server 2025 | All versions |
CPE
Remediation
| |
| Microsoft Windows 10 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | CVE |
| Jun 9, 2026 | CVE Modified | [email protected] |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |
Volerion