GAMES PUBG DED.NET Aims to Fix Live Service Retention After Past Failures PLAYSTATION 5 Fate/EXTRA Record Gameplay Showcase Reveals Combat and Progression Systems PLAYSTATION 5 ANOMALITH Systems Trailer Confirms PS5, Switch 2, and PC Release PHONES Vivo X500 Pro Max Brings 17EV Dynamic Range to Sunset Portraits NINTENDO SWITCH Planted! Launches October 29 with Cross-Play and Co-op Arena Combat NVIDIA Steam Deck Adds 5 Verified Games This Week for Plug-and-Play Gaming NINTENDO Nintendo Direct: Two Consecutive Broadcasts Announced for Zelda 40th Anniversary NINTENDO GTA 6 Switch 2 Listing Appears at French Retailer Alongside PS5, Xbox NINTENDO Nintendo Switch 2 Winter Launch Details Confirmed for September Directs GAMES Blood of Dawnwalker: Imprison Branko to Save Rebels PLAYSTATION 5 Samson: A Tyndalston Story Launches for PS5, Xbox Series on September 21 STEAM DECK Humble Choice September 2026: 8 Games Including Steam Deck Verified Titles GAMES WARDOGS Early Access and 1.0 Launch Dates Explained GAMES The Blood of the Dawnwalker Lets You Beat the Final Boss in the Prologue

Windows Secure Boot Certificates Expire June 24, October 2026

Owen Carter 1 min read

Three 2011-era Microsoft Secure Boot certificates expire in June and October 2026. Windows 11 users get automatic updates; older hardware may need OEM firmware patches.

Windows Secure Boot Certificates Expire June 24, October 2026
SOFTWARE AND UPDATES

Microsoft is rolling out an update to Windows Secure Boot certificates, with three 2011-era certificates set to expire in June and October 2026. The Microsoft Corporation KEK CA 2011 certificate expires on June 24, followed by the Microsoft UEFI CA 2011 on June 27. The final certificate, which signs the Windows bootloader itself, will expire on October 19.

Devices with expired certificates lose future boot-level security patches and revocation lists

Devices with expired certificates will continue to boot normally but lose access to future boot-level security patches and certificate revocation lists. Windows 11 users on supported builds receive these updates automatically through Windows Update. Microsoft has been advancing the rollout of replacement certificates each month since January.

Older hardware may require a matching OEM firmware update to support the new certificate chain, as the updated chain must anchor directly in UEFI firmware. Some manufacturers have stopped issuing firmware updates for older systems, which could leave those devices on the expiring 2011 certificates regardless of Windows updates.

Users can check their Secure Boot status through Windows Security under Device Security. Microsoft provides guidance via support article KB5062710 to help users verify if their system has received the necessary updates or requires additional steps from the device manufacturer.

Source: NotebookCheck