Windows 11 security risk looms: secure boot certificates expire in june 2026
Millions of Windows 11 users face a looming security vulnerability as critical Secure Boot certificates are set to expire in June 2026. Failure to update could leave systems susceptible to malware, even with antivirus software installed.

Secure boot deadline: a cybersecurity wake-up call
The expiration of these certificates, dating back to 2011, affects a significant portion of PCs running Windows 11. Secure Boot is a firmware feature designed to verify the authenticity of the operating system and prevent the loading of unauthorized software, such as bootkits like BlackLotus or rootkits. Without a valid certificate, the system can't properly authenticate, creating a window of opportunity for malicious actors.
Microsoft states that the Microsoft Windows PCA 2011 certificate, along with UEFI CA 2011 certificates, will expire in June 2026. The Microsoft Windows Production PCA 2011 certificate follows in October 2026. While many Windows 11 installations will receive an automatic update via Windows Update, not all will.
How do you know if your PC is vulnerable? A simple check using the msinfo32 command in the Run dialog (Windows+R) will reveal the Secure Boot status. If it's disabled, manual intervention is required. This involves navigating to Settings> System> Recovery> Advanced startup> Restart Now. Then, Troubleshoot> Advanced options> UEFI Firmware Settings> Restart. From there, you can enable Secure Boot in the UEFI settings.
The potential consequences of an expired Secure Boot certificate are severe. Malware could be installed without detection, compromising data and system integrity. This isn't a hypothetical risk; cybercriminals actively exploit vulnerabilities. The risk is amplified by the increasing sophistication of threats targeting Windows systems.
While extending the Extended Security Updates (ESU) program for Windows 10 is an option, Microsoft strongly encourages upgrading to the latest Windows 11 version. The clock is ticking. The window for a smooth transition is narrowing, and delaying action increases the risk of a compromised system. Consider this a critical cybersecurity deadline – one that shouldn’t be ignored.
Don’t wait until June 2026 to address this. A quick system check and potential update could be the difference between a secure computing experience and a significant data breach.