logo

Microsoft rolls out new Secure Boot certificates before June expiration

ID: 297658ed-cc15-5e1a-976c-ca2fb58ca31a

STIX ID: report--297658ed-cc15-5e1a-976c-ca2fb58ca31a

Feed Name: Bleeping Computer

Date Published: 2026-02-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft is replacing its 2011 UEFI Secure Boot certificates via monthly Windows updates ahead of their June 2026 expiration, ensuring continued boot-time protections across supported Windows devices. Many newer PCs already include the updated certificates, but some systems may require OEM firmware updates; Microsoft will auto-update high-confidence devices while offering admins deployment options via Group Policy, registry, and WinCS. Devices that miss the update will enter a degraded security state, and unsupported Windows versions (e.g., Windows 10 without ESU) will not receive the new certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.