securityonline.info 10 Sept 2026, 01:12 UTC

UEFI Shell Flaw Threatens Secure Boot on Millions of Devices

UEFI Shell Flaw Threatens Secure Boot on Millions of Devices
CyberSIXT Evidence Panel

A vulnerability in the UEFI Shell module embedded in SPI flash memory has been disclosed that enables a Secure Boot bypass. Security researchers describe a critical flaw that could let an attacker execute unauthorised code during the early startup phase, potentially loading unverified software before the operating system boots. The issue affects multiple firmware implementations and is tied to three CVEs: CVE-2026-33197, CVE-2026-20293 and CVE-2026-6485.

The highest reported CVSSv4 score is 8.7, with the worst impact described as a BDS Module Bypass Secure Boot Advisory. Patches are available, and users are urged to update to AptioV_5.044.

Affected products span several major vendors. AMI’s AptioV firmware (AptioV) is listed in relation to CVE-2026-33197, Cisco reports a UCS Servers and appliances variation tracked as CVE-2026-20293, Insyde Software tracks CVE-2026-6485, and GIGABYTE has confirmed the issue within its AMI Aptio implementations. Because these vendors supply firmware to numerous secondary manufacturers, the number of potentially vulnerable devices likely runs into millions globally. According to the report, there have been no confirmed exploitations in the wild to date, and no public PoCs are available.

Mitigation focuses on applying OEM firmware updates promptly and tightening Secure Boot configurations. The article notes that updates are not delivered via typical OS patching tools and requires vendor tools or advisories. It also recommends auditing boot configurations and restricting local privileges to modify boot entries, alongside coordinating with endpoint management to integrate firmware updates into maintenance cycles.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline