CVE-2026-8863
CVE-2026-8863
Published: Jun 9, 2026Updated: Jul 23, 2026 Sources: CVE List NVD
Description
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
No summary for this CVE yet.
CVSS Vector Breakdown
Exploitability
AV:LAttack VectorLocal
AC:LAttack ComplexityLow
PR:LPrivileges RequiredLow
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:HConfidentialityHigh
I:HIntegrityHigh
A:HAvailabilityHigh
Affected Products
PC-Doctor
commercialaka pc doctor
Oracle Corporation
commercial·USaka oracle
Spyrus
commercial
baramundi software
commercial·DE
SUSE Linux
commercial·DEaka suse, opensuse
and 2 more affected products View all →
Exploitability
No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.
References
News mentions
8- Old UEFI Shims Expose Systems to Secure Boot Bypassen-us·SecurityWeek· Research UEFI Shim bootloader supply-chain
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Booten·The Hacker News· Advisory UEFI Shim Bootloader ics-ot-iot
- No one knows how many old shims can still bypass UEFI Secure Booten-us·Help Net Security· Research UEFI Secure Boot shims patch-tuesday
- Forgotten UEFI shims undermining Secure Booten·ESET WeLiveSecurity· Research UEFI shim bootloader zero-day
- Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugsen·The Hacker News· Patch Windows patch-tuesday
- Rapid7en·Rapid7 Blog· Roundup Windows Nightmare Eclipse
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsen-us·BleepingComputer· Exploited Windows Collaborative Translation Framework (CTFMON) Nightmare Eclipse
- Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsen-us·BleepingComputer· Patch Windows Collaborative Translation Framework (CTFMON) patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-8863 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
