High severity7.8NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-8863
CVE-2026-8863
Description
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
11- Old UEFI Shims Expose Systems to Secure Boot BypassSecurityWeek · Jul 16, 2026
- Eleven Vulnerable UEFI Shims Enable Secure Boot BypassInfosecurity Magazine · Jul 15, 2026
- 11-Year-Old Linux UEFI Shim Bootloaders Let Attackers Bypass Secure BootCyber Security News · Jul 14, 2026
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootThe Hacker News · Jul 14, 2026
- No one knows how many old shims can still bypass UEFI Secure BootHelp Net Security · Jul 14, 2026
- Forgotten UEFI shims undermining Secure BootESET WeLiveSecurity · Jul 14, 2026
- Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE BugsThe Hacker News · Jun 10, 2026
- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026
- Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)Tenable Blog · Jun 9, 2026
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsBleepingComputer · Jun 9, 2026
- Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsBleepingComputer · Jun 9, 2026