Your windows 11 pc will boot straight into malware in june 2026 unless you swap one expired certificate
Mark the date: 14 June 2026. On that Tuesday morning every Windows 11 machine whose UEFI still trusts the 2011-era certificates will wake up with its Secure Boot gate wide open. No patch Tuesday, no Defender popup, no splash screen—just a silent green light for any bootkit that feels like moving in.
The countdown starts inside the firmware, not windows
Secure Boot is supposed to be the bouncer that checks cryptographic ID cards before the OS even loads. The problem is that those IDs—Microsoft Corporation KEK CA 2011, UEFI CA 2011 and the Windows Production PCA 2011—hit their 15-year expiry simultaneously. Once the x86 firmware reads a dead certificate, the validation chain breaks and the system drops into “anything goes” mode. Antivirus never gets a chance to scan, because the malware is already ring zero.
Microsoft will push the replacement 2023 PCA through Windows Update, but only on hardware that already has Secure Boot toggled on and enrolled with the new keys. If your motherboard shipped with the feature disabled—or if you once disabled it to install a Linux partition—Windows Update will skip the payload. The firmware will continue trusting the 2011 roots until they evaporate, leaving a permanent hole.

Two clicks tell you if you’re on the kill list
Open the Run dialog (Win + R), type msinfo32, scroll to Secure Boot State. If it reads “Off”, you are on the kill list. Flip it on from the UEFI menu, reboot, then hit Check for Updates. The new certificate lands silently in the firmware’s key database; no SKU change, no reinstall, no telemetry opt-in dance.
Skip the step and the exploit kits already circling the WinRAR driver, the BlackLotus bootkit and whatever copycat shows up next will inherit a trust anchor that never questions them. The PC will still boot, the desktop will still sparkle, but every subsequent security layer will be standing on quicksand.
When the clock strikes midnight in June 2026 there will be no second wave, no emergency CAB, no extended support ticket. Either your firmware enrolled the 2023 roots or it didn’t. The machine that misses the deadline won’t just be unsupported—it will be pre-compromised.
