VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

2026-09-22T20:52:01Z•88394f609bf1501e65577c0ce99dbee90fe7dc367ad32d9fc1e2feab00769010
CVE-2026-12780CVE-2026-84286CVE-2026-90999BitLockerCERT/CCOS command injectionSecure Boot bypassUEFIdenial of servicefirmwarekernel drivermachine learningout-of-bounds memory accessphysical disk writepickle deserializationpre-boot executionprivilege escalationprompt injectionremote code executionsupply chain

What happened

CERT/CC advisories describe multiple vulnerabilities, including Secure Boot bypasses through vendor-signed or firmware-embedded UEFI Shell applications, root-level OS command injection in Dokploy backup and restore functions, MLflow pickle deserialization control bypasses enabling code execution, prompt-injection-driven code execution in Sentry Seer, an ExLlamaV3 CUDA out-of-bounds denial of service, and AOMEI Backupper local privilege escalation to UEFI-level code execution. The collection includes several critical pre-boot and arbitrary-code-execution issues, with identified CVEs for Sentry,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
88394f609bf1501e65577c0ce99dbee90fe7dc367ad32d9fc1e2feab00769010
Enrichment time
2026-09-22T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass · Baitaphish