Microsoft released Windows 11 cumulative update KB5124008 for versions 24H2 and 25H2 (OS builds 26100.9445 and 26200.9445), expanding high-confidence device targeting for automatic deployment of replacement Secure Boot certificates. The rollout addresses the expiration of 2011-era Microsoft Secure Boot certificates: the KEK CA and UEFI CA expired in June 2026, and the Windows Production PCA certificate expires on October 19, 2026. The update also includes servicing stack update KB5124007, security and reliability fixes, and updated AI components for Copilot+ PCs.
Organizations and users should keep Windows Update enabled, apply applicable OEM firmware or BIOS updates, and verify that Secure Boot remains enabled in Windows Security. Microsoft said devices awaiting replacement certificates should continue to boot and receive regular Windows updates during the staged deployment. Administrators using Dynamic Update packages must include the version- and architecture-matched boot.stl file in installation media to prevent potential boot failures; Microsoft reported no known issues with KB5124008.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released the Windows 11 cumulative update KB5124008 (OS Builds 26200.9445 and 26100.9445), expanding high-confidence targeting data so more eligible devices can automatically receive replacement Secure Boot certificates. The update also included servicing stack update KB5124007 and reliability and usability fixes.
Microsoft's UEFI CA 2011 Secure Boot certificate expired. It had been used to sign third-party boot loaders, EFI applications, and some option ROMs.
Microsoft's Corporation KEK CA 2011 Secure Boot certificate expired. The certificate had been used to sign updates to Secure Boot's allowed and revoked signature databases, DB and DBX.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.