news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-8863

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.8 High
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk score
62.4
Published
2026-06-09
Status
Published

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.

Weaknesses

CWE-347: Improper Verification of Cryptographic SignatureCWE-354: Improper Validation of Integrity Check Value

Coverage 4

Advisories and references