Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-8863 — Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863 | Kitploit
Tools/GitHubGitHub/0xbekoo/cve-2026-8863
Vulnerability AnalysisHash AnalysisHardware SecurityThreat IntelligenceCurated ResourcesFirmware Analysis
GitHub0xbekoo/cve-2026-8863

CVE-2026-8863

Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863

View Repository
171 month agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-8863

Collection of the signed UEFI Secure Boot shim binaries affected by CVE-2026-8863, with the embedded shim version, Authenticode signer and revocation hashes of each image.

Releases that ship the byte-identical signed shim are collapsed onto a single row — one Authenticode hash is one dbx entry regardless of how many releases carry it.

Check out my blog for more details.

Overview

DistributionReleasesshimEmbedded vendor CA
CentOS7.2, 7.30.9Red Hat Inc.
FedoraServer 24-1.2, 25-1.3, 26-1.5, SoaS 22.3, SoaS 23.100.8Fedora Secure Boot CA
openSUSELeap 42.10.9openSUSE Secure Boot CA
Rockstor Linux3.8-12 / 3.8-9.02, 3.9.0 / 3.9.10.7, 0.9Red Hat Inc.
ROSA LinuxR7, R8 / R90.9NTC IT ROSA LLC
Scientific Linux (SL)7.2, 7.30.9Red Hat Secure Boot (CA key 1)

14 shim images across 6 distributions collapse to 6 unique Authenticode hashes; all are pre-SBAT (0.7, 0.8, 0.9) with no .sbat section, so they can only be retired through a dbx hash revocation.


CentOS

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
7.2, 7.30.9Red Hat Inc.Microsoft Windows UEFI Driver PublisherMicrosoft Corporation UEFI CA 2011eb86fa1386fe6e4533b8b938dcc1250616d2f1c14c15e2fcf80834a161018a0a25469dfdfa56e50fdf4e208fcfac7c8757341019

Fedora

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
Server 24-1.2, 25-1.3, 26-1.5, SoaS 22.3, SoaS 23.100.8Fedora Secure Boot CAMicrosoft Windows UEFI Driver PublisherMicrosoft Corporation UEFI CA 2011dbaf9e056d3d5b38b68553304abc88827ebc00f80cb9c7e197cdbc5822cd316ca070bfbb64dc542d7b6b22de52d9b4d994b0d2f1

openSUSE

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
Leap 42.10.9openSUSE Secure Boot CAMicrosoft Windows UEFI Driver Publisher
openSUSE Secure Boot Signkey
Microsoft Corporation UEFI CA 2011
openSUSE Secure Boot CA
410260b1b6f5af5fbeeb9ea3220658435e876cb3247126ee907a437f312db373c86eeef7791b534ddfef6b79818187dee6919271

Rockstor Linux

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
3.8-12 / 3.8-9.020.7Red Hat Inc.Microsoft Windows UEFI Driver Publisher
Red Hat Inc.
Microsoft Corporation UEFI CA 2011
DigiCert EV Code Signing CA (SHA2)
6dbbead23e8c860cf8b47f74fbfca5204de3e28b881313bb1d1eccdc4747934e3aab12bb9c4b6fc88d1de18f24e45dccd409fc92
3.9.0 / 3.9.10.9Red Hat Inc.Microsoft Windows UEFI Driver PublisherMicrosoft Corporation UEFI CA 2011eb86fa1386fe6e4533b8b938dcc1250616d2f1c14c15e2fcf80834a161018a0a25469dfdfa56e50fdf4e208fcfac7c8757341019

The 3.9.0 / 3.9.1 shim is byte-identical to the CentOS 7.2/7.3 shim above, so both share the single Authenticode hash eb86fa13….

ROSA Linux

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
R7, R8 / R90.9NTC IT ROSA LLCMicrosoft Windows UEFI Driver PublisherMicrosoft Corporation UEFI CA 2011236a9cb0d71951c36398a32eb660ce2cd4a52ccfa7cf751cc6a35d9de549e19b2c5f622319caa15a51fa355459b690174bbb439d

Scientific Linux (SL)

ReleasesshimEmbedded Vendor CASignerIssuer CAAuthenticode SHA256Authenticode SHA1
7.2, 7.30.9Red Hat Secure Boot (CA key 1)Microsoft Windows UEFI Driver PublisherMicrosoft Corporation UEFI CA 20117b2a3f5c96f95bd8086ce54b0825e300f9c8f11fe3401bb631b3215c8de9eb109c95950a60d19a64610dc042334503f8dcaebcc4
Download Tool