CVE-2026-21265
vulnerability analysis and mitigation

Overview

CVE-2026-21265 is a Windows Secure Boot Security Feature Bypass vulnerability caused by the impending expiration of Microsoft's UEFI certificates stored in the KEK and DB databases. Three certificates are affected: Microsoft Corporation KEK CA 2011 (expires 06/24/2026), Microsoft Corporation UEFI CA 2011 (expires 06/27/2026), and Microsoft Windows Production PCA 2011 (expires 10/19/2026). Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. Microsoft disclosed and patched this vulnerability on January 13, 2026, as part of Patch Tuesday. It carries a CVSS v3.1 base score of 6.4 (Medium/High) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-1329 (Reliance on Component That is Not Updateable) — specifically, the OS certificate update protection mechanism depends on firmware components that may contain defects, causing certificate trust updates to fail or behave unpredictably. When the UEFI KEK and DB certificates expire, the Secure Boot trust chain can be disrupted, as the KEK CA signs updates to the DB/DBX, the UEFI CA 2011 signs third-party boot loaders and Option ROMs, and the Windows Production PCA 2011 signs the Windows Boot Manager. Exploitation requires local access and high privileges (CVSS AV:L/AC:H/PR:H), meaning an attacker must already have elevated access to the target system and exploit firmware defects to prevent certificate renewal. No public proof-of-concept exploit code has been confirmed (Microsoft MSRC).

Impact

After certificate expiration, unauthorized boot code execution becomes possible on affected systems, enabling firmware-level malware persistence and complete loss of boot-time security guarantees. An attacker with high privileges and local access could exploit firmware defects to bypass Secure Boot integrity checks, allowing unauthorized code to execute during the boot process before the operating system loads — effectively compromising the entire chain of trust from firmware through the OS. This could facilitate installation of persistent bootkits or rootkits that survive OS reinstallation, and could also allow bypassing of security fixes related to the Windows Boot Manager or Secure Boot (Microsoft MSRC).

Exploitation steps

  1. Gain elevated local access: Obtain high-privilege (administrator/SYSTEM) access to a target Windows system running an unpatched version, using credential theft, privilege escalation, or physical access.
  2. Identify vulnerable firmware: Confirm the target system has firmware with defects in the certificate update protection mechanism that would prevent successful renewal of the expiring UEFI KEK/DB certificates.
  3. Prevent or corrupt certificate update: Exploit firmware defects to cause the certificate trust update process to fail or behave unpredictably, leaving the system reliant on the expiring certificates.
  4. Wait for or simulate certificate expiration: After the KEK CA 2011 (06/24/2026), UEFI CA 2011 (06/27/2026), or Windows Production PCA 2011 (10/19/2026) certificates expire, Secure Boot can no longer validate legitimate boot components.
  5. Deploy unauthorized boot code: With Secure Boot integrity checks bypassed, load a malicious bootloader, UEFI bootkit, or tampered Windows Boot Manager that would otherwise be rejected by Secure Boot, achieving persistent pre-OS execution (Microsoft MSRC).

Indicators of compromise

  • Logs: Windows Event Log entries indicating Secure Boot initialization failures or certificate validation errors during boot; errors in firmware/UEFI logs related to KEK or DB certificate updates failing.
  • System State: Secure Boot status showing as disabled or reporting certificate validation failures via Confirm-SecureBootUEFI PowerShell cmdlet or msinfo32; UEFI variable stores showing outdated or unrenewed certificate entries.
  • File System: Unexpected or unsigned bootloader files in the EFI System Partition (ESP); presence of unknown .efi files in \EFI\ directories.
  • Process/Boot Behavior: Unexpected boot sequence changes; boot manager loading from non-standard paths; persistence of malware or rootkit artifacts that survive OS reinstallation (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on January 13, 2026 as part of Patch Tuesday. Administrators should immediately apply the January 2026 security updates to all affected Windows systems before the certificate expiration dates. Specific patched versions include: Windows 11 24H2 (10.0.26100.7623 or later), Windows 11 25H2 (10.0.26200.7623 or later), Windows 11 23H2 (10.0.22631.6491 or later), Windows 10 22H2 (10.0.19045.6809 or later), Windows 10 21H2 (10.0.19044.6809 or later), Windows 10 1809/Server 2019 (10.0.17763.8276 or later), Windows Server 2022 (10.0.20348.4648 or later), Windows Server 2022 23H2 (10.0.25398.2092 or later), Windows Server 2025 (10.0.26100.32230 or later), and Windows 10 1607/Server 2016 (10.0.14393.8783 or later). After patching, validate that certificate updates complete successfully on all systems, and consider applying firmware updates from system manufacturers that address defects in the certificate update mechanism. Monitor for failed Secure Boot initialization or certificate update errors during and after deployment (Microsoft MSRC).

Community reactions

The vulnerability received broad coverage as part of Microsoft's January 2026 Patch Tuesday, which addressed 114 flaws total. Security vendors including Tenable, Qualys, CrowdStrike, Sophos, and Zero Day Initiative published Patch Tuesday analyses highlighting CVE-2026-21265 as a notable Secure Boot concern (Tenable Blog, ZDI Blog, Sophos Blog). Security researchers noted the vulnerability's significance for UEFI bootkit development, with one blog post specifically discussing how the Secure Boot bypass could be a "gift for next-gen UEFI bootkits." BleepingComputer, The Hacker News, The Register, and Infosecurity Magazine all covered the January 2026 Patch Tuesday release, with the Secure Boot certificate expiration issue noted as a unique and complex remediation challenge (BleepingComputer).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management