Microsoft Warns Secure Boot May Be Bypassed as Windows UEFI Certificates Expire
Microsoft has released updates addressing a critical security feature bypass vulnerability in Windows Secure Boot certificates, identified as CVE-2026-21265. These updates were included in the January 2026 Patch Tuesday release.
Microsoft has released updates addressing a critical security feature bypass vulnerability in Windows Secure Boot certificates, identified as CVE-2026-21265. These updates were included in the January 2026 Patch Tuesday release.
The vulnerability arises from expiring certificates issued in 2011, which are integral to Secure Boot's trust chain. If left unpatched, they could allow attackers to compromise boot integrity.
This issue is rated as Important with a CVSS v3.1 base score of 6.4. Exploitation requires local access, high privileges, and a high level of attack complexity, decreasing the likelihood of a successful attack.
The vulnerability occurs because Microsoft certificates stored in UEFI KEK and DB are approaching expiration in mid-2026. Without updates, Secure Boot functionality may be at risk.
Firmware defects in the operating system's certificate update mechanism can disrupt the trust chain, affecting Windows Boot Manager and third-party loaders. While publicly disclosed, this vulnerability has not been exploited in the wild. Microsoft recommends the immediate deployment of 2023 replacement certificates.
Three key 2011 certificates require renewal to maintain Secure Boot:
Microsoft Corporation KEK CA 2011 : Signs updates to DB and DBX, expiring on Tue, Jun 24, 2026. Microsoft Corporation UEFI CA 2011 : Signs third-party boot loaders and Option ROMs, expiring on Fri, Jun 27, 2026. Microsoft Windows Production PCA 2011 : Signs the Windows Boot Manager, expiring on Sun, Oct 19, 2026.
Failure to update these certificates exposes devices to boot-time attacks, as highlighted in Microsoft's November 2025 advisory.
These updates were included in the January 2026 Patch Tuesday release.
Patches are available for legacy Windows Server and extended-support editions, with customer action required.
Product KB Article Build Number Update Type
Windows Server 2012 R2 (Core) 5073696 6.3.9600.22968 Monthly Rollup
Windows Server 2012 R2 5073696 6.3.9600.22968 Monthly Rollup
Windows Server 2012 (Core) 5073698 6.2.9200.25868 Monthly Rollup
Windows Server 2012 5073698 6.2.9200.25868 Monthly Rollup
Windows Server 2016 (Core) 5073722 10.0.14393.8783 Security Update
Windows Server 2016 5073722 10.0.14393.8783 Security Update
Windows 10 Version 1607 x64 5073722 10.0.14393.8783 Security Update
Windows 10 Version 1607 x86 5073722 10.0.14393.8783 Security Update
Organizations with IT-managed or Microsoft-managed updates should prioritize deployment. It is recommended to verify firmware compatibility to prevent post-patch boot issues.
Based on reporting by Cyber Security News.
