Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baramundi Software
Baramundi Software baramundi Management Suite Blancco Uk Blancco Uk whitecanyon Wipedrive Finland Matriculation Board Finland Matriculation Board abitti 1 Ntc It Rosa Ntc It Rosa rosalinux Oracle Corporation Oracle Corporation oracle Linux Pc-doctor Pc-doctor factory For Linux Pc-doctor network Factory For Linux Pc-doctor service Center Pc-doctor service Center Drive Erase Pc-doctor service Center Enterprise Pc-doctor service Center Japan Spyrus Spyrus wtgcreator |
|
| Vendors & Products |
Baramundi Software
Baramundi Software baramundi Management Suite Blancco Uk Blancco Uk whitecanyon Wipedrive Finland Matriculation Board Finland Matriculation Board abitti 1 Ntc It Rosa Ntc It Rosa rosalinux Oracle Corporation Oracle Corporation oracle Linux Pc-doctor Pc-doctor factory For Linux Pc-doctor network Factory For Linux Pc-doctor service Center Pc-doctor service Center Drive Erase Pc-doctor service Center Enterprise Pc-doctor service Center Japan Spyrus Spyrus wtgcreator |
Tue, 09 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-287 |
|
| References |
| |
| Metrics |
ssvc
|
Tue, 09 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple version of UEFI SHIM bootloaders are vulnerable to SecureBoot bypass through lack of enforcement and validation SBAT. The following authenticode signatures are impacted by this disclosure AE75F0D82BA3DF824FBFC69340CC3B4D66C598373B1AB54CDB6C8BFD83A6B961 - Spyrus WTGCreator version 4.2 FD23D6E57DE6F4E1F9D7118DA1C5F31A8AF6BE5E5D9E8170F9493447268D50C5 - Baramundi Management Suite up to 2024R1 - A0DE9333442C1BF9349A460141AE5E80F911955C6506040FA3D021BF6C1AE3E4 WhiteCanyon WipeDrive versions 8.0.0 through 8.1.3. 95B6D71FC0C0F8C5E1533A37AEF92CF6B0C961E2CC612A97117FA6759CE5FC06 - Finland Matriculation Exam Abitti 1 version 1.0.0 236A9CB0D71951C36398A32EB660CE2CD4A52CCFA7CF751CC6A35D9DE549E19B - NTC IT Rosa R9, R10 8A964D5F8373948D20A1D4296FB92E545DAD4617A0C810F3B934B53D98AE8963 - PC-Doctor Service Center 15, 16 | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders. |
Tue, 09 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple version of UEFI SHIM bootloaders are vulnerable to SecureBoot bypass through lack of enforcement and validation SBAT. The following authenticode signatures are impacted by this disclosure AE75F0D82BA3DF824FBFC69340CC3B4D66C598373B1AB54CDB6C8BFD83A6B961 - Spyrus WTGCreator version 4.2 FD23D6E57DE6F4E1F9D7118DA1C5F31A8AF6BE5E5D9E8170F9493447268D50C5 - Baramundi Management Suite up to 2024R1 - A0DE9333442C1BF9349A460141AE5E80F911955C6506040FA3D021BF6C1AE3E4 WhiteCanyon WipeDrive versions 8.0.0 through 8.1.3. 95B6D71FC0C0F8C5E1533A37AEF92CF6B0C961E2CC612A97117FA6759CE5FC06 - Finland Matriculation Exam Abitti 1 version 1.0.0 236A9CB0D71951C36398A32EB660CE2CD4A52CCFA7CF751CC6A35D9DE549E19B - NTC IT Rosa R9, R10 8A964D5F8373948D20A1D4296FB92E545DAD4617A0C810F3B934B53D98AE8963 - PC-Doctor Service Center 15, 16 | |
| Title | CVE-2026-8863 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published: 2026-06-09T18:10:15.426Z
Updated: 2026-06-10T15:16:35.228Z
Reserved: 2026-05-18T19:41:10.790Z
Link: CVE-2026-8863
Updated: 2026-06-09T19:41:27.054Z
Status : Deferred
Published: 2026-06-09T19:17:59.210
Modified: 2026-06-09T21:17:26.447
Link: CVE-2026-8863
No data.
ReportizFlow