Security researchers discovered a critical Secure Boot bypass vulnerability impacting multiple major hardware vendors today. This flaw exists within the Unified Extensible Firmware Interface (UEFI) Shell module embedded directly in SPI flash memory. An attacker can exploit this weakness to run unauthorized code during the early system startup phase.
- Product: AMI AptioV, Cisco Enterprise NFV Infrastructure Software +1
- Vulnerabilities: 3 flaws (CVE-2026-33197, CVE-2026-20293, CVE-2026-6485)
- Highest severity: 8.7 (High · CVSSv4)
- Worst impact: BDS Module Bypass Secure Boot Advisory
- Status: No confirmed exploitation yet; patches available
- Action: Update to AptioV_5.044 now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-33197 | 8.7 | BDS Module Bypass Secure Boot Advisory | AptioV_5.044 | Not exploited |
| CVE-2026-6485 | 8.2 | CWE-489 | — | Not exploited |
| CVE-2026-20293 | 7.1 | CWE-749 | — | Not exploited |
Why This Threat Matters
The UEFI protocol initializes hardware before loading the operating system. Secure Boot normally guarantees that only trusted, digitally signed software executes during this phase. However, a Secure Boot bypass vulnerability destroys this foundational trust. Malicious code executed here can install persistent bootkits. These implants survive full operating system reinstalls.
Furthermore, early execution evades standard endpoint detection and response tools. The rootkits loaded through this method can hide their presence from antivirus scanners entirely. They operate at a hardware level that the operating system cannot control. Enterprise environments face massive risks from this exposure. Many organizations rely strictly on OS-level security software. Those tools cannot detect pre-boot memory modifications.
How the Attack Works
Many motherboard manufacturers include a UEFI Shell for diagnostic purposes. Because this shell operates before the operating system, it provides dangerous commands. These commands can access physical memory directly. Usually, system firmware removes the shell boot option when Secure Boot is active.
Eclypsium researcher Stas Lyakhov discovered a critical oversight in this removal process. An attacker with local privileges can modify the UEFI boot configuration. They create multiple redundant boot entries pointing to the shell. This action overwhelms the removal logic. The advisory explains the mechanism clearly. It states, “An attacker with the ability to modify UEFI boot configuration may be able to create multiple boot option entries and bypass controls intended to prevent the UEFI Shell from launching.” Once inside the shell, the attacker uses memory modify commands. They overwrite memory values related to security enforcement. Finally, they load their own unverified software payloads.
Affected Versions
This vulnerability impacts several major firmware providers. American Megatrends Incorporated (AMI) tracks its specific AptioV flaw under CVE-2026-33197. Cisco confirmed that UCS Servers and appliances suffer from a variation tracked as CVE-2026-20293. Additionally, Insyde Software tracks its vulnerable components under CVE-2026-6485. GIGABYTE also confirmed the issue within its own AMI Aptio implementations.
These vendors supply firmware to numerous secondary manufacturers. As a result, the true number of vulnerable devices likely spans millions of units globally. Security researchers have not confirmed any active exploitation in the wild. Likewise, no public proof-of-concept exploits are currently available.
Patch and Mitigation Steps
System administrators must apply OEM firmware updates immediately. GIGABYTE and Cisco have already scheduled BIOS patches for their hardware. Updating firmware often requires specific vendor tools. These updates do not deploy automatically through standard operating system patching mechanisms. You can review specific vendor instructions in the official CERT/CC vulnerability note.
Enterprises should audit their Secure Boot configurations tightly. IT teams must restrict local administrative privileges. This action prevents unauthorized users from modifying the boot entry tables. Furthermore, organizations should consult their endpoint management vendors. They must integrate firmware updates into regular maintenance cycles.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!