
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21265 is a Windows Secure Boot Security Feature Bypass vulnerability caused by the impending expiration of Microsoft's UEFI certificates stored in the KEK and DB databases. Three certificates are affected: Microsoft Corporation KEK CA 2011 (expires 06/24/2026), Microsoft Corporation UEFI CA 2011 (expires 06/27/2026), and Microsoft Windows Production PCA 2011 (expires 10/19/2026). Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. Microsoft disclosed and patched this vulnerability on January 13, 2026, as part of Patch Tuesday. It carries a CVSS v3.1 base score of 6.4 (Medium/High) (Microsoft MSRC).
The root cause is classified as CWE-1329 (Reliance on Component That is Not Updateable) — specifically, the OS certificate update protection mechanism depends on firmware components that may contain defects, causing certificate trust updates to fail or behave unpredictably. When the UEFI KEK and DB certificates expire, the Secure Boot trust chain can be disrupted, as the KEK CA signs updates to the DB/DBX, the UEFI CA 2011 signs third-party boot loaders and Option ROMs, and the Windows Production PCA 2011 signs the Windows Boot Manager. Exploitation requires local access and high privileges (CVSS AV:L/AC:H/PR:H), meaning an attacker must already have elevated access to the target system and exploit firmware defects to prevent certificate renewal. No public proof-of-concept exploit code has been confirmed (Microsoft MSRC).
After certificate expiration, unauthorized boot code execution becomes possible on affected systems, enabling firmware-level malware persistence and complete loss of boot-time security guarantees. An attacker with high privileges and local access could exploit firmware defects to bypass Secure Boot integrity checks, allowing unauthorized code to execute during the boot process before the operating system loads — effectively compromising the entire chain of trust from firmware through the OS. This could facilitate installation of persistent bootkits or rootkits that survive OS reinstallation, and could also allow bypassing of security fixes related to the Windows Boot Manager or Secure Boot (Microsoft MSRC).
Confirm-SecureBootUEFI PowerShell cmdlet or msinfo32; UEFI variable stores showing outdated or unrenewed certificate entries..efi files in \EFI\ directories.Microsoft released patches on January 13, 2026 as part of Patch Tuesday. Administrators should immediately apply the January 2026 security updates to all affected Windows systems before the certificate expiration dates. Specific patched versions include: Windows 11 24H2 (10.0.26100.7623 or later), Windows 11 25H2 (10.0.26200.7623 or later), Windows 11 23H2 (10.0.22631.6491 or later), Windows 10 22H2 (10.0.19045.6809 or later), Windows 10 21H2 (10.0.19044.6809 or later), Windows 10 1809/Server 2019 (10.0.17763.8276 or later), Windows Server 2022 (10.0.20348.4648 or later), Windows Server 2022 23H2 (10.0.25398.2092 or later), Windows Server 2025 (10.0.26100.32230 or later), and Windows 10 1607/Server 2016 (10.0.14393.8783 or later). After patching, validate that certificate updates complete successfully on all systems, and consider applying firmware updates from system manufacturers that address defects in the certificate update mechanism. Monitor for failed Secure Boot initialization or certificate update errors during and after deployment (Microsoft MSRC).
The vulnerability received broad coverage as part of Microsoft's January 2026 Patch Tuesday, which addressed 114 flaws total. Security vendors including Tenable, Qualys, CrowdStrike, Sophos, and Zero Day Initiative published Patch Tuesday analyses highlighting CVE-2026-21265 as a notable Secure Boot concern (Tenable Blog, ZDI Blog, Sophos Blog). Security researchers noted the vulnerability's significance for UEFI bootkit development, with one blog post specifically discussing how the Secure Boot bypass could be a "gift for next-gen UEFI bootkits." BleepingComputer, The Hacker News, The Register, and Infosecurity Magazine all covered the January 2026 Patch Tuesday release, with the Secure Boot certificate expiration issue noted as a unique and complex remediation challenge (BleepingComputer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."