Microsoft warned that Secure Boot certificates issued in 2011 are nearing expiration and that devices which do not receive the newer 2023 Secure Boot update will generally keep booting, but may stop receiving future boot-chain protections. The gap affects some older Windows systems whose OEMs no longer provide compatible BIOS or UEFI updates, as well as devices running Legacy BIOS, CSM mode, or unsupported Windows 11 configurations with Secure Boot disabled. Microsoft is reportedly skipping incompatible hardware rather than forcing updates that could cause failures, but enterprises may still face compliance, cyber-insurance, and lifecycle-management pressure because those endpoints could miss future DBX revocations, Windows Boot Manager updates, and mitigations for bootloader threats such as BlackLotus.
The transition is also creating planning challenges beyond Windows. Linux distributions that rely on Microsoft-signed shim loaders are expected to continue booting on systems that already trust the older Microsoft UEFI CA, but older PCs that never receive firmware updates with the 2023 certificates may have trouble booting newer Linux media or releases. The issue follows Microsoft's broader effort to harden the pre-boot environment after flaws such as CVE-2024-21302, a Windows Secure Kernel Mode elevation-of-privilege bug that could let an administrator roll back VBS-related files to bypass protections; Microsoft responded with boot-time code integrity policies, an optional SkuSiPolicy.p7b revocation policy, and stronger protections on newer Windows releases. Administrators are being urged to verify Secure Boot update status, update firmware and recovery media where possible, and document compensating controls or replace hardware that cannot be brought forward.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After the June 2026 Secure Boot certificate expirations, major PC vendors including ASUS, Lenovo, Dell, HP, Surface, MSI, Acer, Samsung, and LG published customer guidance on completing the move to Microsoft's 2023 certificates. The guidance emphasized that some systems need OEM BIOS or firmware updates in addition to Windows Update, and noted issues such as HP BitLocker recovery loops and firmware partition limits on some older devices.
The new reference says the Microsoft UEFI CA 2011 certificate is set to expire on 2026-06-27, extending the Secure Boot trust-chain transition beyond the initial June 24 expiration. It notes Linux distributions are affected because many rely on this certificate to sign shim, and systems without the 2023 replacements may fail to trust newly signed boot components.
Microsoft's Secure Boot 2011 certificates begin expiring on June 24, 2026. Reporting notes this does not immediately stop older Windows PCs from booting, but it can prevent affected systems from receiving future boot-level security updates such as DBX revocations and Boot Manager updates.
Ahead of the first 2011 Secure Boot certificate expiration on June 24, 2026, Microsoft expanded the rollout of replacement 2023 Secure Boot certificates to eligible Windows 10 and Windows 11 devices. The update preserves the ability to receive future boot-level security updates, and Microsoft added Windows Security status reporting plus guidance about firmware incompatibilities and OEM BIOS updates.
ZDNET reported that Microsoft Secure Boot certificates from 2011 are approaching expiration in 2026, raising concerns about future Linux boot compatibility on UEFI systems. The article says existing systems should generally keep booting, but older PCs without firmware updates carrying Microsoft's 2023 Secure Boot certificates may not boot newer Linux distributions.
Microsoft published guidance for CVE-2024-21302, a Windows Secure Kernel Mode elevation of privilege vulnerability that can let an administrator roll back VBS-related system files to vulnerable versions. The guidance describes mitigations including a default-enabled Microsoft-signed CI policy and an optional revocation policy, SkuSiPolicy.p7b, along with deployment and recovery considerations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcecybersecuritynews.com
Open sourcezdnet.com
Open sourcewindowslatest.com
Open sourcezdnet.com
Open sourcewired.com
Open sourcewindowslatest.com
Open sourcezdnet.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.