CVE-2026-8863
Summary
| CVE | CVE-2026-8863 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 19:17:59 UTC |
| Updated | 2026-06-09 21:17:26 UTC |
| Description | Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from ADP
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-347: Improper Verification of Cryptographic Signature | CWE-354: Improper Validation of Integrity Check Value
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Oracle Corporation | OracleLinux7.2 Shim | affected 0.9 | Not specified |
| CNA | PC-Doctor | Service Center Enterprise | affected 14 17.0.7536.900 custom | Not specified |
| CNA | PC-Doctor | Service Center Drive Erase | affected 15 17.0.7538.592 custom | Not specified |
| CNA | PC-Doctor | Service Center Japan | affected 15 17.0.7539.904 custom | Not specified |
| CNA | PC-Doctor | Service Center | affected 14 17.0.7535.900 custom | Not specified |
| CNA | PC-Doctor | Network Factory For Linux Bootable Diagnostics | affected 6.9 6.20.7711.267 custom | Not specified |
| CNA | PC-Doctor | Factory For Linux Bootable Diagnostics | affected 6.9 6.20.7710.267 custom | Not specified |
| CNA | Spyrus | WTGCreator | affected 4.2 | Not specified |
| CNA | Blancco UK | WhiteCanyon WipeDrive | affected 8.0.0 8.1.3 custom | Not specified |
| CNA | Baramundi Software | Baramundi Management Suite | affected * 2024R1 custom | Not specified |
| CNA | Finland Matriculation Board | Abitti 1 | affected 1.0.0 | Not specified |
| CNA | NTC IT ROSA LLC | RosaLinux | affected R9 | Not specified |
| CNA | NTC IT ROSA LLC | RosaLinux | affected R10 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kb.cert.org/vuls/id/616257 | [email protected] | kb.cert.org | |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863 | [email protected] | msrc.microsoft.com | |
| www.kb.cert.org/vuls/id/616257 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Thanks to Martin Smolar of ESET for discovering and reporting this vulnerability (en)
There are currently no legacy QID mappings associated with this CVE.