Microsoft's rollout of the Windows 11 Secure Boot 2023 certificate update continues to cause operational problems across enterprise and deployment environments, with administrators reporting BitLocker recovery loops, KEK update failures, and incorrect Secure Boot status on older PCs. Reports from Microsoft's OEM discussions indicate the issues affect multiple vendors rather than a single manufacturer, with HP fleets including EliteBook and ZBook systems repeatedly entering recovery and some Dell devices also impacted even after BIOS updates and documented remediation steps. Microsoft has reportedly paused deployment on certain firmware and device combinations because of known compatibility problems.
The same rollout is also being linked to broader boot and update disruptions. Some Windows 11 systems now require multiple reboots during major monthly updates because Secure Boot certificate installation is being staged alongside other components such as .NET updates, and Microsoft has not yet completed deployment despite earlier expectations. Separately, administrators have reported Winload.efi errors during PXE and USB-based boot scenarios across Lenovo hardware, including cases using updated SCCM images and Microsoft's ADK, suggesting the certificate transition may also be affecting imaging and recovery workflows; some devices are additionally logging SCEP enrollment errors tied to TPM attestation requests, though those messages are generally considered non-critical.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A sysadmin Reddit post described Winload.efi errors when PXE booting Windows machines and when booting from a USB containing only Microsoft's ADK, across multiple Lenovo models. The poster said the issue persisted despite updated firmware and BIOS, SCCM 2603 with new certificates in the WIM, and regardless of whether UEFICA2023STATUS was set to Updated.
WindowsLatest reported that some Windows 11 systems installing large monthly updates such as the July 2026 Patch Tuesday release may reboot twice instead of once. The article attributed the behavior mainly to separate .NET Framework installation steps and Microsoft's ongoing Secure Boot 2023 certificate rollout, including KB5101650.
During Microsoft's July 15 OEM Secure Boot Office Hours event, IT administrators reported persistent problems tied to the Windows 11 Secure Boot 2023 certificate rollout, including BitLocker recovery loops, KEK update failures, and incorrect Secure Boot status reporting across enterprise fleets. Several HP and Dell cases remained unexplained by the end of the session, and Microsoft indicated rollout had been paused on some device and firmware combinations due to known firmware issues.
Microsoft published guidance stating that legacy Microsoft Secure Boot certificates used in the UEFI trust chain would begin expiring in June 2026 and that organizations needed to update to 2023-era certificates. The post warned that unprepared devices and VMs could lose Secure Boot updateability and miss future boot security protections, and it provided rollout recommendations including OEM firmware updates and an opt-in registry key for managed updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcewindowslatest.com
Open sourcereddit.com
Open sourcewindowslatest.com
Open sourcetechcommunity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.