Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisorystandards-framework-updateembedded-device-vulnerability

Microsoft Secure Boot Certificate Refresh Ahead of 2011 Certificate Expiration

Updated 3d agoFirst seen Feb 10, 202648 sources

Microsoft has started deploying updated Secure Boot certificates via regular monthly Windows updates to replace the original 2011-era certificates that begin expiring in late June 2026. Secure Boot, introduced in 2011 for UEFI-based systems, helps prevent pre-OS malware (e.g., bootkits/rootkits) by allowing only trusted, properly signed boot components to load, using a certificate chain anchored in UEFI firmware and validated against trusted signature databases.

The expiring components include Microsoft-issued certificates used in the Secure Boot trust chain (including the Key Exchange Key (KEK) and Microsoft UEFI CA/Production CA certificates), which are present on most PCs built since 2011 and also affect many Linux distributions that rely on Microsoft’s UEFI signing ecosystem. Microsoft says the refresh will be automatic for in-support Windows devices where updates are Microsoft-managed, while organizations can also control deployment through their own management tooling; the effort is positioned as a large-scale ecosystem maintenance activity involving coordination across many OEM firmware configurations.

Share:
Microsoft Secure Boot Certificate Refresh Ahead of 2011 Certificate Expiration
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

18 events from the most recent confirmed update back to the earliest known activity.

18 EVENTS
May 23, 20269d ago

Dell publishes BIOS guidance to update Secure Boot active database

Dell published a support advisory explaining how customers can update the Secure Boot active database directly from BIOS. The guidance provides Dell-specific remediation steps as part of the industry transition to the newer Secure Boot certificates ahead of the June 2026 expiration of the legacy 2011 chain.

How To Update Secure Boot Active Database from BIOS | Dell US
May 17, 202615d ago

Microsoft explains new Windows SecureBoot folder after May update

Microsoft confirmed that the C:\Windows\SecureBoot folder created by the May 2026 Windows 11 update is expected behavior tied to the Secure Boot certificate transition, not a bug. The company said the folder contains example PowerShell scripts mainly for IT administrators and noted some devices may still miss the new certificates if their firmware is outdated.

Microsoft confirms the new Secure Boot folder in Windows 11 isn't a bug, you don't need to delete it
May 12, 202620d ago

Microsoft releases May Windows 11 update KB5089549 with Secure Boot protections

On 2026-05-12, Microsoft released the mandatory Windows 11 24H2/25H2 Patch Tuesday update KB5089549. The update continued preparations for the June 2026 Secure Boot certificate expiration and also tightened driver trust by removing default trust for cross-signed drivers.

Windows 11 KB5089549 out with faster performance, direct download links for offline installer (.msu)
Apr 30, 20261mo ago

Microsoft says April Secure Boot rollout may trigger multiple Windows 11 restarts

Microsoft said some Windows 11 systems may restart more than once while April 2026 updates install Secure Boot 2023 certificates, describing the behavior as an expected one-time part of the update process. The company indicated the certificate rollout expanded with the April 2026 updates, including the optional update released on April 30.

Microsoft confirms Windows 11 may restart multiple times after updates and your PC isn't broken, as it's due to Secure Boot 2023
Apr 29, 20261mo ago

Microsoft publishes Surface Secure Boot certificate guidance

Microsoft published a support article for Surface devices explaining the Secure Boot certificate transition and related update requirements. The guidance indicates Surface-specific documentation and support steps were made available ahead of the June 2026 expiration of the legacy 2011 certificates.

Surface Secure Boot Certificates | Microsoft Support
Apr 19, 20261mo ago

Microsoft warns April out-of-band update may trigger BitLocker recovery

On 2026-04-19, Microsoft disclosed that a limited subset of mainly IT-managed devices could prompt for a BitLocker recovery key on first restart after installing out-of-band update KB5091157 during the Secure Boot 2023 transition. Microsoft said the issue affects systems with specific PCR7 and BitLocker configurations, recommended removing the explicit PCR7 Group Policy or applying a Known Issue Rollback, and said a permanent fix would come in a future update.

April 19, 2026-KB5091157 (OS Build 26100.32698) Out-of-band - Microsoft Support
Apr 14, 20262mo ago

April Patch Tuesday delivers Secure Boot status indicator in Windows

Microsoft's April 2026 Patch Tuesday updates for Windows 10 and Windows 11 added a visual Secure Boot status indicator in the Windows Security app. The feature helps users verify whether updated Secure Boot certificates are installed before the legacy 2011 certificates begin expiring in June 2026.

La dernière mise à jour de Windows confirme si votre PC est proté ...
Apr 7, 20262mo ago

Microsoft adds Secure Boot certificate status to Windows Security app

Microsoft said it is updating the Windows Security app to show Secure Boot certificate status indicators and clearer guidance for users as the 2011 certificates approach expiration. The change is intended to help users understand whether their systems have current certificates and what action, if any, is needed.

Windows Secure Boot Certificates From 2011 Will Be Expiring Soon. What You Need to Know - CNET
Mar 1, 20263mo ago

Microsoft details Secure Boot rollout edge cases in March 2026 AMA

In March 2026, Microsoft engineers discussed the Secure Boot certificate transition in an AMA, outlining deployment edge cases and enterprise guidance. They said Legacy BIOS systems are skipped, Secure Boot-disabled devices must be properly enabled before receiving the update, and environments using PXE, Hyper-V, Windows Server, or customized Secure Boot configurations require special handling and testing.

Microsoft reveals what happens to Windows 11 PCs if you ignore the Secure Boot deadline in June 2026
Feb 11, 20264mo ago

OEMs coordinate firmware updates for affected systems

PC manufacturers including HP, Dell, Lenovo, Asus, and Microsoft published or referenced guidance for firmware and BIOS updates needed on older devices to support the new Secure Boot certificates. HP specifically said it is working with Microsoft to provide updates for supported Windows 11 PCs before the legacy certificates expire.

Feb 10, 20264mo ago

Microsoft begins broad rollout of refreshed Secure Boot certificates

Microsoft began rolling out updated Secure Boot certificates through monthly Windows updates for supported devices, with automatic delivery for systems using Microsoft-managed updates. The company said some systems will also need OEM firmware updates before the new certificates can be applied.

Microsoft publicly warns of June 2026 Secure Boot certificate expiration

On February 10, 2026, Microsoft and multiple outlets highlighted that the original 2011 Secure Boot certificates will begin expiring in late June 2026. Microsoft said devices that miss the update will still boot but will enter a degraded security state with reduced boot-level protections and limited ability to receive future pre-boot mitigations.

Microsoft releases February Windows update with Secure Boot changes

On February 10, 2026, Microsoft released Windows 11 23H2 cumulative update KB5075941, which included Secure Boot-related changes. The update refreshes Boot Manager components on devices that already trust the Windows UEFI CA 2023 certificate.

Jan 1, 20265mo ago

Microsoft starts limited deployment of new certificates to some Windows 11 devices

Since January 2026, Microsoft has been deploying refreshed Secure Boot certificates to some Windows 11 24H2 and 25H2 systems. This marked the beginning of the broader rollout ahead of the June 2026 expiration deadline.

Oct 23, 20257mo ago

Microsoft ships KB5070879 with early Secure Boot expiration warning

On 2025-10-23, Microsoft released out-of-band update KB5070879 for Windows Server 23H2. The support notice warned that commonly used Secure Boot certificates would begin expiring in June 2026 and urged organizations to review guidance and update certificates in advance.

October 23, 2025-KB5070879 (OS Build 25398.1916) Out-of-band - Microsoft Support
Sep 5, 20259mo ago

Microsoft publishes Secure Boot key management guidance for hardware partners

Microsoft published Windows Secure Boot key creation and management guidance on Microsoft Learn for OEMs and device manufacturers. The documentation provided implementation guidance ahead of the broader 2026 rollout tied to the expiration of the legacy 2011 Secure Boot certificates.

Windows Secure Boot Key Creation and Management Guidance | Microsoft Learn
Jan 1, 20242y ago

New PCs begin shipping with updated Secure Boot certificates

Many newly built devices started shipping with the newer Secure Boot certificates baked into firmware in 2024, reducing the need for later remediation. Reports indicate most systems shipped in 2025 already include the updated trust anchors.

Jan 1, 20233y ago

Microsoft issues replacement Secure Boot certificates

Microsoft issued new Secure Boot certificates in 2023 to replace the original 2011 trust chain that is set to expire in June 2026. The new certificates form the basis of a long-term transition for Windows devices and OEM firmware.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Secure Boot Certificate Refresh Ahead of 2011 Certificate Expiration | Mallory