Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Medium

UEFI Secure Boot Security Feature Bypass in Windows Boot Loader

IdentifiersCVE-2026-0390CWE-807· Reliance on Untrusted Inputs in a…

CVE-2026-0390 is an Important security feature bypass vulnerability in the Windows Boot Loader, described by Microsoft as caused by reliance on untrusted inputs in a security decision. The issue affects the UEFI Secure Boot trust path in Windows Boot Loader and allows a locally authorized attacker to bypass a security mechanism. Available advisory context indicates the flaw is tied to an authentication-related feature in the boot process and can enable impersonation. No specific vulnerable function or code path was provided in the supplied content.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an authorized local attacker with high privileges to bypass a Windows Boot Loader security feature associated with UEFI Secure Boot. The supplied advisory context states this can bypass an authentication-related protection and allow impersonation. This undermines platform boot trust and weakens security assurances normally enforced during the boot chain.

Remediation

Patch, then assume compromise.

Apply the official Microsoft security update for the affected Windows Boot Loader components. Use the Microsoft Security Update Guide and the relevant Windows product updates for supported versions to ensure the Secure Boot/Boot Loader fixes are installed.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationWindows 10 1607operating_system
Microsoft CorporationWindows 10 1809operating_system
Microsoft CorporationWindows 10 21h2operating_system
Microsoft CorporationWindows 10 22h2operating_system
Microsoft CorporationWindows Server 2016operating_system
Microsoft CorporationWindows Server 2019operating_system
Microsoft CorporationWindows Server 2022operating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.