VU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass
2026-06-10T20:52:15Z•6935d53ca2cf2d7c0f44bcc8b1b0d09857bf68ec3e7cfdc22f49d54affac5947
AppsmithBYOVDChrome extensionCodeMirrorCollibraDBXIMSIPsecSIPSecure BootSecurlyUEFIVerizonVoLTEXSSZip-Slipaccess-controlbootloadercross-site-scriptinginsecure-transportintegritypath-traversalplaintext-keysshimweak-cryptography
What happened
Batch of CERT/CC vulnerability notes covering multiple high-impact issues: Microsoft‑signed UEFI shim bootloaders (older shim versions) permit Secure Boot bypass (to be mitigated by adding affected signatures to Microsoft’s DBX); Securly Chrome extension (v3.0.7) exposes insecure HTTP downloads, hardcoded AES keys, and unauthenticated endpoints leading to data exposure and manipulation; Verizon VoLTE IMS was observed sending SIP signaling without IPsec integrity protection, enabling interception and tampering; Appsmith’s CodeMirror SQL autocomplete contains stored XSS (CVE-2026-7299) allowing任
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 6935d53ca2cf2d7c0f44bcc8b1b0d09857bf68ec3e7cfdc22f49d54affac5947
- Enrichment time
- 2026-06-10T20:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.