VU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypass

2026-06-10T20:52:15Z6935d53ca2cf2d7c0f44bcc8b1b0d09857bf68ec3e7cfdc22f49d54affac5947
AppsmithBYOVDChrome extensionCodeMirrorCollibraDBXIMSIPsecSIPSecure BootSecurlyUEFIVerizonVoLTEXSSZip-Slipaccess-controlbootloadercross-site-scriptinginsecure-transportintegritypath-traversalplaintext-keysshimweak-cryptography

What happened

Batch of CERT/CC vulnerability notes covering multiple high-impact issues: Microsoft‑signed UEFI shim bootloaders (older shim versions) permit Secure Boot bypass (to be mitigated by adding affected signatures to Microsoft’s DBX); Securly Chrome extension (v3.0.7) exposes insecure HTTP downloads, hardcoded AES keys, and unauthenticated endpoints leading to data exposure and manipulation; Verizon VoLTE IMS was observed sending SIP signaling without IPsec integrity protection, enabling interception and tampering; Appsmith’s CodeMirror SQL autocomplete contains stored XSS (CVE-2026-7299) allowing任

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
6935d53ca2cf2d7c0f44bcc8b1b0d09857bf68ec3e7cfdc22f49d54affac5947
Enrichment time
2026-06-10T20:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.