Windows 11 secure boot certificates expiring in 2026: a security risk

A critical security update for Windows 11 is fast approaching, potentially leaving millions of PCs vulnerable to sophisticated malware. The certificates that underpin the operating system's core security feature, Secure Boot, are set to expire in June 2026. Failure to address this could render systems susceptible to attacks from sophisticated threats like bootkits and rootkits, even if antivirus software is installed.

n

Secure boot certificates face expiration, raising security concerns

Secure boot certificates face expiration, raising security concerns

Secure Boot, a UEFI firmware feature, acts as a gatekeeper, verifying the authenticity of software before it’s allowed to run. This process ensures that only digitally signed files from trusted sources, like Microsoft, can initiate the boot process. When these certificates expire, the system loses its ability to validate software integrity, creating an opening for malicious actors.

n

The expiration impacts several key certificates: Microsoft Windows PCA 2011, UEFI CA 2011, and UEFI CA 2011*. The most significant impact will come from the Microsoft Windows Production PCA 2011 certificate, slated to expire in October 2026. While Windows 10 has officially ended security support, those still running it with extended security updates until October 2026 should prioritize upgrading to Windows 11. The risk of prolonged exposure to vulnerabilities far outweighs the inconvenience of a system migration.

n

Fortunately, Microsoft is automating the replacement of these certificates for most Windows 11 users through Windows Update. However, it’s crucial to verify the status of Secure Boot on your system. You can check this using the msinfo32 command (run by typing