Executive Summary
In July 2026, researchers discovered a critical vulnerability in Microsoft's Secure Boot, a feature designed to protect devices from firmware infections. This flaw, present for 13 of Secure Boot's 14-year existence, allowed attackers to bypass protections using outdated, signed firmware images known as shims. These shims, some dating back to 2013, remained signed by Microsoft despite known defects, enabling unauthorized code execution during system boot and facilitating persistent malware infections.
This incident underscores the importance of rigorous certificate management and timely revocation processes. The prolonged exposure highlights potential oversight in Microsoft's security protocols, emphasizing the need for continuous monitoring and updating of security measures to prevent similar vulnerabilities. (pcgamer.com)
Why This Matters Now
The discovery of this long-standing vulnerability in Secure Boot highlights the critical need for organizations to reassess and strengthen their firmware security protocols. As attackers increasingly exploit such foundational weaknesses, ensuring robust and up-to-date security measures is imperative to protect against persistent threats.
Attack Path Analysis
Attackers exploited unrevoked, vulnerable shims to bypass Secure Boot, gaining initial access. They then escalated privileges by executing malicious code during the boot process. Lateral movement was achieved by deploying malware across the network. Command and control were established through persistent backdoors. Data exfiltration occurred via encrypted channels. The impact included system compromise and potential data theft.
Kill Chain Progression
Initial Compromise
Description
Attackers utilized unrevoked, vulnerable shims to bypass Secure Boot protections, allowing unauthorized code execution during the boot process.
Related CVEs
CVE-2024-7344
CVSS 8.2A vulnerability in a UEFI application signed by Microsoft's third-party UEFI certificate allows attackers to bypass Secure Boot, enabling execution of untrusted code during system boot.
Affected Products:
Microsoft UEFI Secure Boot – All versions prior to January 14, 2025
Exploit Status:
exploited in the wildCVE-2026-10797
CVSS 7.8Outdated Microsoft-signed UEFI shim bootloaders can be exploited to bypass Secure Boot, allowing execution of unsigned code during system boot.
Affected Products:
Microsoft UEFI Secure Boot – All versions prior to June 2026
Exploit Status:
exploited in the wildCVE-2026-8863
CVSS 7.8Vulnerable UEFI shim bootloaders signed by Microsoft allow attackers to bypass Secure Boot, facilitating the deployment of malicious UEFI bootkits.
Affected Products:
Microsoft UEFI Secure Boot – All versions prior to June 2026
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
System Firmware
Bootkit
Bypass User Account Control
Token Impersonation/Theft
Safe Mode Boot
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Hardware
Microsoft Secure Boot vulnerability enables firmware-level supply-chain attacks, bypassing foundational UEFI security protections across motherboard manufacturers and hardware vendors globally.
Computer Software/Engineering
13-year Secure Boot bypass affects Linux distributions and utility software using vulnerable shims, compromising software integrity verification and boot-time security controls.
Government Administration
Critical infrastructure faces supply-chain compromise through trivial Secure Boot bypass, threatening national security systems dependent on firmware-level trust and integrity validation.
Health Care / Life Sciences
Medical device firmware vulnerable to supply-chain attacks via Secure Boot bypass, potentially compromising patient safety systems and HIPAA compliance requirements.
Sources
- Long-Lived Vulnerability in Microsoft Secure Boothttps://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.htmlVerified
- ESET Research discovers UEFI Secure Boot bypass vulnerabilityhttps://www.eset.com/us/about/newsroom/press-releases/eset-research-discovers-uefi-secure-boot-bypass-vulnerability/Verified
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowhttps://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/Verified
- Microsoft UEFI shim Secure Boot bypass (CVE-2026-10797, CVE-2026-8863)https://cybersixt.com/incidents/eset-warns-outdated-microsoft-uefi-shims-can-bypass-secure-boot-49e64524Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute unauthorized code during the boot process would likely be constrained, reducing the risk of initial system compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across the network would likely be constrained, reducing the spread of malware.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing data loss.
The overall impact of the attack would likely be constrained, reducing the extent of system compromise and data theft.
Impact at a Glance
Affected Business Functions
- System Boot Integrity
- Firmware Security
- Malware Prevention
Estimated downtime: N/A
Estimated loss: N/A
Potential for unauthorized code execution during system boot, leading to persistent malware installations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit the spread of malware and restrict unauthorized lateral movement.
- • Enhance East-West Traffic Security to monitor and control internal network communications, detecting anomalous activities.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block malicious outbound traffic.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and enforce consistent security policies across environments.
- • Regularly update and revoke vulnerable shims and certificates to maintain the integrity of Secure Boot and prevent exploitation.



