Microsoft has started deploying updated Secure Boot certificates via regular monthly Windows updates to replace the original 2011-era certificates that begin expiring in late June 2026. Secure Boot, introduced in 2011 for UEFI-based systems, helps prevent pre-OS malware (e.g., bootkits/rootkits) by allowing only trusted, properly signed boot components to load, using a certificate chain anchored in UEFI firmware and validated against trusted signature databases.
The expiring components include Microsoft-issued certificates used in the Secure Boot trust chain (including the Key Exchange Key (KEK) and Microsoft UEFI CA/Production CA certificates), which are present on most PCs built since 2011 and also affect many Linux distributions that rely on Microsoft’s UEFI signing ecosystem. Microsoft says the refresh will be automatic for in-support Windows devices where updates are Microsoft-managed, while organizations can also control deployment through their own management tooling; the effort is positioned as a large-scale ecosystem maintenance activity involving coordination across many OEM firmware configurations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
Dell published a support advisory explaining how customers can update the Secure Boot active database directly from BIOS. The guidance provides Dell-specific remediation steps as part of the industry transition to the newer Secure Boot certificates ahead of the June 2026 expiration of the legacy 2011 chain.
Microsoft confirmed that the C:\Windows\SecureBoot folder created by the May 2026 Windows 11 update is expected behavior tied to the Secure Boot certificate transition, not a bug. The company said the folder contains example PowerShell scripts mainly for IT administrators and noted some devices may still miss the new certificates if their firmware is outdated.
On 2026-05-12, Microsoft released the mandatory Windows 11 24H2/25H2 Patch Tuesday update KB5089549. The update continued preparations for the June 2026 Secure Boot certificate expiration and also tightened driver trust by removing default trust for cross-signed drivers.
Microsoft said some Windows 11 systems may restart more than once while April 2026 updates install Secure Boot 2023 certificates, describing the behavior as an expected one-time part of the update process. The company indicated the certificate rollout expanded with the April 2026 updates, including the optional update released on April 30.
Microsoft published a support article for Surface devices explaining the Secure Boot certificate transition and related update requirements. The guidance indicates Surface-specific documentation and support steps were made available ahead of the June 2026 expiration of the legacy 2011 certificates.
On 2026-04-19, Microsoft disclosed that a limited subset of mainly IT-managed devices could prompt for a BitLocker recovery key on first restart after installing out-of-band update KB5091157 during the Secure Boot 2023 transition. Microsoft said the issue affects systems with specific PCR7 and BitLocker configurations, recommended removing the explicit PCR7 Group Policy or applying a Known Issue Rollback, and said a permanent fix would come in a future update.
Microsoft's April 2026 Patch Tuesday updates for Windows 10 and Windows 11 added a visual Secure Boot status indicator in the Windows Security app. The feature helps users verify whether updated Secure Boot certificates are installed before the legacy 2011 certificates begin expiring in June 2026.
Microsoft said it is updating the Windows Security app to show Secure Boot certificate status indicators and clearer guidance for users as the 2011 certificates approach expiration. The change is intended to help users understand whether their systems have current certificates and what action, if any, is needed.
In March 2026, Microsoft engineers discussed the Secure Boot certificate transition in an AMA, outlining deployment edge cases and enterprise guidance. They said Legacy BIOS systems are skipped, Secure Boot-disabled devices must be properly enabled before receiving the update, and environments using PXE, Hyper-V, Windows Server, or customized Secure Boot configurations require special handling and testing.
PC manufacturers including HP, Dell, Lenovo, Asus, and Microsoft published or referenced guidance for firmware and BIOS updates needed on older devices to support the new Secure Boot certificates. HP specifically said it is working with Microsoft to provide updates for supported Windows 11 PCs before the legacy certificates expire.
Microsoft began rolling out updated Secure Boot certificates through monthly Windows updates for supported devices, with automatic delivery for systems using Microsoft-managed updates. The company said some systems will also need OEM firmware updates before the new certificates can be applied.
On February 10, 2026, Microsoft and multiple outlets highlighted that the original 2011 Secure Boot certificates will begin expiring in late June 2026. Microsoft said devices that miss the update will still boot but will enter a degraded security state with reduced boot-level protections and limited ability to receive future pre-boot mitigations.
On February 10, 2026, Microsoft released Windows 11 23H2 cumulative update KB5075941, which included Secure Boot-related changes. The update refreshes Boot Manager components on devices that already trust the Windows UEFI CA 2023 certificate.
Since January 2026, Microsoft has been deploying refreshed Secure Boot certificates to some Windows 11 24H2 and 25H2 systems. This marked the beginning of the broader rollout ahead of the June 2026 expiration deadline.
On 2025-10-23, Microsoft released out-of-band update KB5070879 for Windows Server 23H2. The support notice warned that commonly used Secure Boot certificates would begin expiring in June 2026 and urged organizations to review guidance and update certificates in advance.
Microsoft published Windows Secure Boot key creation and management guidance on Microsoft Learn for OEMs and device manufacturers. The documentation provided implementation guidance ahead of the broader 2026 rollout tied to the expiration of the legacy 2011 Secure Boot certificates.
Many newly built devices started shipping with the newer Secure Boot certificates baked into firmware in 2024, reducing the need for later remediation. Reports indicate most systems shipped in 2025 already include the updated trust anchors.
Microsoft issued new Secure Boot certificates in 2023 to replace the original 2011 trust chain that is set to expire in June 2026. The new certificates form the basis of a long-term transition for Windows devices and OEM firmware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
48 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcewindowslatest.com
Open sourcedell.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.