UEFI SHIM SBAT Bypass in SecureBoot Bootloaders (v4.22024R1 etc)
CVE-2026-8863 Published on June 9, 2026
CVE-2026-8863
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.
Vulnerability Analysis
CVE-2026-8863 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Products Associated with CVE-2026-8863
Want to know whenever a new CVE is published for Oracle? stack.watch will email you.
Affected Versions
Oracle Corporation OracleLinux(7.2) shim:- Version 0.9 is affected.
- Version 14, <= 17.0.7536.900 is affected.
- Version 15, <= 17.0.7538.592 is affected.
- Version 15, <= 17.0.7539.904 is affected.
- Version 14, <= 17.0.7535.900 is affected.
- Version 6.9, <= 6.20.7711.267 is affected.
- Version 6.9, <= 6.20.7710.267 is affected.
- Version 4.2 is affected.
- Version 8.0.0, <= 8.1.3 is affected.
- Version *, <= 2024R1 is affected.
- Version 1.0.0 is affected.
- Version R9 is affected.
- Version R10 is affected.