CERT/CC UEFI DBX mitigation for vendor-signed applications
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT/CC issued mitigation guidance to apply UEFI Forbidden Signature Database (DBX) updates, reducing Secure Boot bypass risk for affected vendor-signed UEFI applications. The advisory covers binaries from Acer, AMD, ASUS, ECS, Getac, GIGABYTE, Toshiba, and Uniwill. Administrators are being told to revoke trust in the affected binaries before they can execute during boot.
Related Happenings
UEFI shim Secure Boot bypass (multiple vulnerabilities)
Vulnerability
H score1
First: 14.07.2026 15:46
Last: 14.07.2026 15:46
Sources 1
About this happening:
Researchers identified 11 old, Microsoft-signed UEFI shim bootloaders that can bypass Secure Boot on systems trusting the Microsoft Corporation UEFI CA 2011 certificat...
UEFI shim Secure Boot bypass (multiple vulnerabilities)
VulnerabilityAbout this happening: Researchers identified 11 old, Microsoft-signed UEFI shim bootloaders that can bypass Secure Boot on systems trusting the Microsoft Corporation UEFI CA 2011 certificat...
Latest development: 15.07.2026 17:00
Microsoft revoked the vulnerable Microsoft-signed UEFI shim bootloaders in the dbx update shipped with the June 9 Patch Tuesday, closing the Secure Boot bypass tracked as CVE-2026-8863 and CVE-2026-10797. Windows machines should update automatically, while Linux users can pull the revocation through the Linux Vendor Firmware Service.
U-Boot FIT signature-check and image-parsing flaws memory corruption flaw
Vulnerability
H score1
First: 10.07.2026 18:57
Last: 10.07.2026 18:57
Sources 1
About this happening:
U-Boot has six newly disclosed flaws in its FIT signature-checking and image-parsing path, putting routers, smart cameras, and data-center server management chips...
U-Boot FIT signature-check and image-parsing flaws memory corruption flaw
VulnerabilityAbout this happening: U-Boot has six newly disclosed flaws in its FIT signature-checking and image-parsing path, putting routers, smart cameras, and data-center server management chips...
MacOS XPC cached signature trust privilege escalation privilege-escalation flaw
Vulnerability
H score23
First: 25.06.2026 14:00
Last: 25.06.2026 14:00
Sources 1
About this happening:
macOS XPC trusted software verification lets a non-root user abuse cached signature trust to call privileged helper functions without authentication, opening a route to ...
MacOS XPC cached signature trust privilege escalation privilege-escalation flaw
VulnerabilityAbout this happening: macOS XPC trusted software verification lets a non-root user abuse cached signature trust to call privileged helper functions without authentication, opening a route to ...
GIGABYTE security patch release for CVE-2026-4415
Security Patch Release
H score39
First: 01.04.2026 01:28
Last: 01.04.2026 01:28
Sources 1
About this happening:
GIGABYTE is directing users of Control Center to upgrade to 25.12.10.01 to mitigate CVE-2026-4415, a flaw that exposed systems to remote file writes. The update ma...
GIGABYTE security patch release for CVE-2026-4415
Security Patch ReleaseAbout this happening: GIGABYTE is directing users of Control Center to upgrade to 25.12.10.01 to mitigate CVE-2026-4415, a flaw that exposed systems to remote file writes. The update ma...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
Vulnerability
H score39
First: 18.03.2026 13:42
Last: 18.03.2026 13:42
Sources 1
About this happening:
Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
Timeline
-
19.06.2026 21:33 2 articles · 26d ago
CERT/CC advises DBX updates to block Secure Boot bypass on vulnerable UEFI applications
Mitigation Patch UpdateCERT/CC advises system administrators to apply updates to the UEFI Forbidden Signature Database (DBX) to revoke trust in affected vendor-signed binaries from Acer, AMD, ASUS, ECS, Getac, GIGABYTE, Toshiba, and Uniwill. The guidance is intended to prevent a BYOVD attack path that could let an attacker with administrative privileges or physical access execute arbitrary code during the early pre-boot phase before the operating system initializes.
Show sources
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes — thehackernews.com — 19.06.2026 21:33
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes — thehackernews.com — 19.06.2026 21:33