Vulnerability intelligence
CVE-2026-8863
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
CVSS Score
7.8
High
EPSS — Exploit Probability
0.1%
Riskier than 1% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 16, 2026 · latest Jul 16, 2026
Tracked incidents
Coverage timeline
-
ESET warns outdated Microsoft UEFI shims can bypass Secure Bootwww.securityweek.com · Jul 16, 2026