UEFI Shell in SPI flash can bypass Secure Boot (VU#718077): AMI Aptio and Cisco UCS affected, firmware patches rolling out
CERT/CC's VU#718077, reported by Eclypsium researcher Stas Lyakhov, describes how a UEFI Shell embedded in SPI flash can be used to bypass Secure Boot and execute unauthorized pre-boot code; AMI (CVE-2026-33197) and Cisco UCS Servers and UCS-based appliances…
CERT/CC published Vulnerability Note VU#718077 on 2026-09-08 (15:05:58Z), reported by Eclypsium researcher Stas Lyakhov: a UEFI Shell embedded in SPI flash can be abused by attackers who can modify UEFI boot configuration, creating multiple boot entries that bypass controls preventing the Shell from launching under Secure Boot. The Shell's dmem and mm commands allow arbitrary physical memory read/write, letting attackers overwrite Secure Boot values and execute unauthorized pre-boot code; CERT/CC says such code can persist across reboots and OS reinstalls while degrading EDR effectiveness. AMI confirmed its Aptio UEFI BDS module is affected (CVE-2026-33197), and Cisco published an advisory on 2026-09-08 (16:00:00Z) for a variation affecting UCS Servers and UCS-based appliances (CVE-2026-20293), in which UEFI Shell memory write commands remain available while Secure Boot is enabled, allowing modification of UEFI memory to bypass validation checks and run unauthorized software. The sources describe exploitation preconditions differently: CERT/CC says exploitation requires the ability to modify UEFI boot entries (e.g., with root privileges), while Cisco says it requires valid credentials for a user or admin account or unauthenticated physical access to select the UEFI Shell boot option at boot time. They also characterize impact differently: CERT/CC emphasizes persistence across reboots and OS reinstalls and reduced EDR effectiveness, whereas Cisco says impact is limited to bypassing Secure Boot validation to execute unauthorized software and affects firmware boot integrity rather than the running operating system. CVE-2026-6485 is also listed among the CERT/CC note's CVEs without further detail in the reports. Vendor firmware patches are available and being rolled out through OEM and IBV BIOS build pipelines; enterprises are advised to audit and monitor UEFI boot configuration changes.
- CERT/CC Vulnerability Note VU#718077, published 2026-09-08 (15:05:58Z) and reported by Eclypsium researcher Stas Lyakhov, describes a UEFI Shell embedded in SPI flash that can be used to bypass Secure Boot and execute unauthorized pre-boot…
- Attackers create multiple boot entries that bypass controls preventing the Shell from launching under Secure Boot; the Shell's dmem and mm commands allow arbitrary physical memory read/write, enabling overwrite of Secure Boot values…
- AMI confirmed its Aptio UEFI BDS module is affected (CVE-2026-33197).
- Cisco published an advisory on 2026-09-08 (16:00:00Z) for a variation affecting UCS Servers and UCS-based appliances (CVE-2026-20293), in which UEFI Shell memory write commands remain available while Secure Boot is enabled.
- Exploitation preconditions differ by source: CERT/CC says attackers need the ability to modify UEFI boot entries (e.g., with root privileges); Cisco says exploitation requires valid user or admin credentials or unauthenticated physical…
- Impact is characterized differently: CERT/CC says pre-boot code can persist across reboots and OS reinstalls and reduce EDR effectiveness; Cisco says impact is limited to bypassing Secure Boot validation to execute unauthorized software…
- CVE-2026-6485 is listed among the CERT/CC note's CVEs but is not further described in either report.
- Vendor firmware patches are available and being rolled out through OEM and IBV BIOS build pipelines (CERT/CC); enterprises are advised to audit and monitor UEFI boot configuration changes.
Coverage timelineoldest first · each row is one article
- · 8d agoVU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
CERT/CC Vulnerability Notes· 55
CERT/CC details VU#718077: UEFI Shell embedded in SPI flash lets attackers bypass Secure Boot and execute pre-boot code; patches issued.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20293 | Secure Boot Bypass via UEFI Shell in Cisco UCS Servers and UCS-based Appliances CVE-2026-20293 is a flaw in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances that lets an attacker bypass UEFI Secure Boot validation and run unauthorized software. It is triggered because memory-write commands remain available in the UEFI Shell even while Secure Boot is enabled: an attacker selects the UEFI Shell boot option at boot time and uses shell commands to modify UEFI memory variables and overwrite Secure Boot-related memory values. A successful exploit manipulates the preboot environment and allows execution of untrusted software that would normally be rejected by Secure Boot. Exploitation requires either physical access (no credentials needed) or valid credentials for an account with the user or admin role on the affected system, so practical exposure is limited to systems where an attacker has local access. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS puts 30-day exploitation probability at about 0.1%. Do: Upgrade UCS server and appliance firmware to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-20293 (specific versions are not included in the data provided). Until patched, restrict physical access to UCS hosts, limit local user/admin credentials, and restrict or remove the UEFI Shell option from the boot menu so it cannot be selected at boot time. Because exploitation requires local access and there is no known in-the-wild exploitation, prioritize systems that are physically accessible or widely shared (e.g., branch or lab locations). | 7.1 | <1% |
| largeon the order of hundreds of thousands of deployed UCS servers and UCS-based appliances worldwide (estimated from Cisco's large enterprise server installed base) | ||
| CVE-2026-33197 | Privileged local BIOS code execution in AMI Aptio V (incomplete input validation) AMI's Aptio V UEFI BIOS firmware contains an input-validation flaw classified as CWE-184 (Incomplete List of Disallowed Inputs), meaning a BIOS code path fails to reject all inputs it is supposed to disallow. Triggering it requires local access to the machine, and the CVSS 4.0 metrics show the attacker must already hold high privileges (typically OS-level administrator), with no user interaction needed but elevated attack prerequisites that must be met. Successful exploitation yields arbitrary code execution in the firmware context with high impact on confidentiality, integrity and availability on the affected system and, per the scoring, potentially on subsequent systems - significant for BIOS because firmware-level compromise can persist across OS reinstalls. Any workstation, server or motherboard shipped with AMI Aptio V firmware by an OEM is in scope. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported (EPSS 0.1%); a separate related AMI firmware issue (VU#718077, Secure Boot bypass via a UEFI Shell embedded in SPI flash) is also documented. Do: Check your motherboard or system vendor's support page for BIOS updates incorporating the AMI fix, since no affected-version list is provided here and OEMs package Aptio V fixes in their own BIOS releases. Until patched, restrict local administrative access on sensitive systems and treat this as a high-severity firmware fix rather than a routine BIOS update. While updating, also verify whether your system's SPI flash contains the embedded UEFI Shell module highlighted in VU#718077, which can be used to bypass Secure Boot. | 8.7 | <1% |
| masson the order of tens of millions of installed systems (OEM boards shipping with AMI Aptio V firmware) | ||
| CVE-2026-6485 | Secure Boot bypass via embedded UEFI Shell in UEFI BIOS firmware (CVE-2026-6485) CVE-2026-6485 (CWE-489, active code left in production firmware) describes a UEFI Shell module embedded in the SPI Flash of affected UEFI BIOS images that can be used to bypass Secure Boot. An attacker with local access and high privileges (CVSS AV:L/PR:H) — for example a local administrator or someone with physical access — can run shell commands or execute startup scripts through the embedded shell, launching code that Secure Boot does not verify. The result is a break in the Secure Boot chain of trust, allowing unsigned or attacker-controlled code to run at boot (e.g., to install bootkit- or firmware-level persistence), which is why the CVSS scope is 'changed' (S:C) with high impact to confidentiality, integrity, and availability. Affected systems are those whose UEFI BIOS ships with this embedded UEFI Shell module in SPI Flash; the issue is tracked in CERT/CC VU#718077, but the exact vendor, product list, and version ranges are not specified in the available data. There is no known exploitation at this time: no public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days. Do: Follow CERT/CC VU#718077 for vendor statements and apply the BIOS/firmware update from the affected BIOS vendor as soon as it is released; in the meantime, determine whether your fleet's BIOS images include an embedded UEFI Shell module in SPI Flash (via the vendor's documentation, boot menu, or a CHIPSEC/UEFI firmware audit). Where the BIOS setup allows, disable booting into the embedded UEFI Shell or execution of startup scripts, and restrict local administrative and physical access to sensitive systems, since the flaw requires high local privileges and is primarily a Secure Boot/persistence hardening risk rather than a remote threat. | 8.2 | <1% |
| unknown |