Microsoft is urging Windows 11 users to update their Secure Boot certificates before the current 2011-issued credentials expire in June 2026 to prevent potential security vulnerabilities and boot failures.
Key Points
- Current Secure Boot certificates issued in 2011 are scheduled to expire in June 2026, necessitating a transition to new 2023 certificates.
- Failure to update may prevent the installation of future Windows feature updates and stop the delivery of critical malware blacklists.
- Outdated certificates leave systems vulnerable to bootkit malware because the firmware will no longer receive essential security updates for boot-critical binaries.
- Users can verify their system status by navigating to the Device Security section within the Windows Security app settings.
- The new 2023 certificates are valid through 2038 and require a firmware-level update process that may cause the PC to restart multiple times.