VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

2026-09-23T08:52:02Z•277c54247c9cf609f3e74e7c13cbe4c793b271167f25b398cfc0d1d621c933b9
CVE-2026-12780CVE-2026-84286CVE-2026-90999aomei-backuppercommand-injectiondenial-of-servicedokployexllamav3firmwarekernel-drivermlflowos-command-injectionout-of-bounds-accessphysical-disk-writepickle-deserializationpre-boot-executionprivilege-escalationprompt-injectionremote-code-executionsecure-boot-bypasssentry-seersupply-chainuefi

What happened

CERT/CC vulnerability notes describe multiple high-impact vulnerabilities across UEFI firmware and signed shell applications, Dokploy, MLflow, Sentry Seer, ExLlamaV3, AOMEI Backupper, and Skullcandy Dime devices. Impacts include Secure Boot bypass and pre-boot code execution, root-level OS command injection, arbitrary code execution through unsafe pickle deserialization or prompt injection, denial of service, and local privilege escalation with physical-disk writes. Vendors and users should apply available updates, disable risky automated workflows or exposed UEFI shells where applicable, and,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
277c54247c9cf609f3e74e7c13cbe4c793b271167f25b398cfc0d1d621c933b9
Enrichment time
2026-09-23T08:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass · Baitaphish