VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass
2026-09-23T08:52:02Z•277c54247c9cf609f3e74e7c13cbe4c793b271167f25b398cfc0d1d621c933b9
CVE-2026-12780CVE-2026-84286CVE-2026-90999aomei-backuppercommand-injectiondenial-of-servicedokployexllamav3firmwarekernel-drivermlflowos-command-injectionout-of-bounds-accessphysical-disk-writepickle-deserializationpre-boot-executionprivilege-escalationprompt-injectionremote-code-executionsecure-boot-bypasssentry-seersupply-chainuefi
What happened
CERT/CC vulnerability notes describe multiple high-impact vulnerabilities across UEFI firmware and signed shell applications, Dokploy, MLflow, Sentry Seer, ExLlamaV3, AOMEI Backupper, and Skullcandy Dime devices. Impacts include Secure Boot bypass and pre-boot code execution, root-level OS command injection, arbitrary code execution through unsafe pickle deserialization or prompt injection, denial of service, and local privilege escalation with physical-disk writes. Vendors and users should apply available updates, disable risky automated workflows or exposed UEFI shells where applicable, and,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 277c54247c9cf609f3e74e7c13cbe4c793b271167f25b398cfc0d1d621c933b9
- Enrichment time
- 2026-09-23T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.