securityonline.info 6/15/2026, 2:10:47 AM · external

UEFI shim bug CVE-2026-35273 enables Secure Boot bypass

UEFI shim bug CVE-2026-35273 enables Secure Boot bypass
Developing story vulnerability 30 articles tracked
CISA adds Oracle PeopleSoft CVE-2026-35273 to KEV catalog
CyberSIXT Evidence Panel
Primary Source kb.cert.org
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-35273) has been identified in outdated UEFI shim bootloaders, threatening multiple operating systems by enabling Secure Boot bypass exploits. Attackers can exploit these flaws during early boot phases, bypassing operating system defenses and allowing persistent system compromise. This issue affects various vendors including RedHat, Oracle, and OpenSuse, who are using unpatched versions.

Microsoft's response includes updates to its UEFI Forbidden Signature Database (DBX) to revoke trust in vulnerable bootloaders. Best practices for enterprise administrators involve updating signature databases and testing revocation lists to ensure system integrity against advanced attacks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline