# Forgotten UEFI shims undermining Secure Boot

DevFeed: [Forgotten UEFI shims undermining Secure Boot](<https://devfeed.tech/articles/forgotten-uefi-shims-undermining-secure-boot-8369.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/>)

Author: Martin Smolár

Published: 2026-07-14T08:53:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [boot](<https://devfeed.tech/tags/boot.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [os](<https://devfeed.tech/tags/os.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

ESET reported 11 outdated UEFI shim bootloaders that can bypass Secure Boot on systems trusting Microsoft's third-party UEFI certificate. Microsoft revoked the reported shim hashes in its June 2026 Patch Tuesday dbx update.

## Source excerpt

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities