PT-2026-2766 · Microsoft · Corporation Kek Ca 2011+3

Published

2026-01-13

·

Updated

2026-03-10

·

CVE-2026-21265

CVSS v3.1

6.4

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows versions (affected versions not specified) Windows Server versions (affected versions not specified)
Description The issue centers around the approaching expiration of Microsoft certificates used in Windows Secure Boot, specifically those stored in the UEFI KEK and DB. These certificates, originally issued in 2011, are set to expire in June and October 2026. The expiration of these certificates could weaken boot integrity or cause boot failures if updated certificates are not deployed. The operating system’s certificate update mechanism relies on firmware components that may have defects, potentially leading to failures or unpredictable behavior during certificate trust updates. This could disrupt the Secure Boot trust chain. The vulnerability allows attackers to affect the system by bypassing security features. The issue impacts devices globally that utilize Secure Boot. The vulnerability is actively exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-00477
CVE-2026-21265

Affected Products

Corporation Kek Ca 2011
Corporation Uefi Ca 2011
Windows Production Pca 2011
Windows