Since June 2026, millions of Windows computers began to expire Secure Boot certificates, which were issued back in 2011. The computer will not “die” and will not refuse to boot, but will gradually lose protection from one of the most dangerous types of attacks — bootkits, which infect the system even before Windows itself starts.
Certificates from 2011 have expired
Secure Boot is a mechanism that checks: the code that runs when you turn on the computer, before the operating system itself starts, is actually signed by a trusted developer and not slipped by an attacker. This works through a combination of UEFI firmware of the motherboard and cryptographic certificates — a kind of “identity certificate” for the bootloader program code, explains xrust. It was these certificates that Microsoft issued in 2011, when the Secure Boot technology itself was just being introduced into mass computers — and any certificate, like a passport, has an expiration date.
Fifteen years later, the deadline has come. The first of the old certificates — Microsoft Corporation KEK CA 2011 — expired on June 24, 2026, followed by Microsoft UEFI CA 2011 on June 27. The third, Microsoft Windows Production PCA 2011, will last the longest — until October 19, 2026. Microsoft was preparing a replacement in advance: new certificates issued in 2023, designed for use until 2038.
What will actually happen to the computer
Here Microsoft tried to reduce panic as much as possible: the expiration of old certificates does not in itself block the computer from booting. The system will continue to start as normal, Windows updates will be installed as before.
The problem is different — that it will stop happening. A device that has not received the new certificates will lose updates for the Windows Boot Manager itself, the latest versions of the Secure Boot databases and, most importantly, updates to the so-called DBX — the revocation list, which contains digital signatures of already compromised, malicious boot code. Simply put, the computer will no longer receive a “blacklist” of new bootkits and will lose protection against new vulnerabilities at the boot level — even if Windows itself continues to update as normal.
What does the BlackLotus malware have to do with it
Updating certificates is not routine a formality, but a direct consequence of real attacks in recent years. One of the most famous examples is the BlackLotus bootkit, which is capable of bypassing Secure Boot and attaching itself to the system at the bootloader level, from where it is extremely difficult to detect with a conventional antivirus: the malware starts before the operating system and its protective mechanisms can turn on. It was the response to such attacks that prompted Microsoft, along with updating the certificates, to carry out a broader modernization of the protection of the early boot stage — with new trusted anchors, the company will be able to more quickly release updated bootloader components and revoke compromised signatures as new threats emerge.
- Если Вам понравилась статья, рекомендуем почитать
- Meta crashes prices for AI programmer, challenging Anthropic and OpenAI
- Microsoft has officially confirmed Copilot Super App: Windows is preparing for its biggest AI update







