logo

Expiring Microsoft Secure Boot Keys May Block DBX Updates on Legacy Devices

ID: 642b867f-c7e6-52f0-8938-a4718c83a40d

STIX ID: report--642b867f-c7e6-52f0-8938-a4718c83a40d

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Mayura Kathir

...
...

On June 27, 2026 the Microsoft Corporation KEK CA 2011 and Microsoft UEFI CA 2011 expire (with Windows Production PCA 2011 expiring in October 2026), which will not prevent devices from booting but will stop KEK‑authorized DB/DBX updates via Windows Update; devices that remain on the 2011 chain will be unable to receive new Secure Boot protections or revocations and thus remain permanently vulnerable to bootkit-style threats (e.g., BootHole, BlackLotus) unless administrators apply OEM firmware updates, enroll the 2023 certificates, re-sign Linux shim builds, and follow Microsoft’s migration guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.