Banx Media Platform logo
TECHNOLOGY

Windows Updates Steer Clear of a Security Sunset by Refreshing Secure Boot Certificates

Microsoft’s January 2026 updates include automatic replacement of expiring Secure Boot certificates with newer ones, ensuring Windows systems continue to trust and validate boot components securely into 2026 and beyond.

T

Tama Billar

EXPERIENCED
5 min read
12 Views
Credibility Score: 89/100
Windows Updates Steer Clear of a Security Sunset by Refreshing Secure Boot Certificates

In the latest January 2026 monthly Windows Update, Microsoft has quietly begun a critical update that refreshes expiring Secure Boot certificates on Windows devices — an unusual but necessary fix to keep system security intact as foundational cryptographic trust anchors approach their expiration dates. This automated replacement is rolling out now to eligible systems and is part of Microsoft’s broader effort to ensure that Secure Boot continues to protect PCs from malware early in the startup process.

Secure Boot is a security feature built into UEFI firmware that checks the digital signatures of system boot components — such as bootloaders and low-level drivers — against a trusted set of certificate authorities stored in firmware. When Secure Boot is enabled, the machine will only start software that can be cryptographically verified, helping block boot-level malware like rootkits.

Microsoft originally shipped key Secure Boot certificates — including the Microsoft Corporation KEK CA 2011, Microsoft Windows Production PCA 2011, and Microsoft Corporation UEFI CA 2011 — with devices starting around Windows 8. These certificates are set to begin expiring in June 2026, with some phases continuing into October. If systems continue to rely on these older certificates after that point, they may no longer trust or validate new Secure Boot-signed components properly or receive future boot-level security patches.

To prevent this, the January 2026 cumulative updates include a phased rollout of new Secure Boot certificates issued in 2023, delivered automatically to supported devices that meet Microsoft’s readiness and update criteria. These updated certificates replace the older ones in the firmware’s Secure Boot certificate databases so Windows devices can continue to establish a trusted boot path and accept future signed boot components and mitigations.

The process is designed to be safe and gradual: Microsoft’s update logic first verifies that a device has successfully applied recent servicing stack and quality updates before delivering the new certificates. For most home users with automatic Windows Updates enabled, no special action is required — the system will receive the certificates as part of the regular patch cycle.

For IT administrators and managed fleets, Microsoft provides guidance on monitoring and deploying these certificate updates, including registry, OEM firmware checks, and Group Policy methods, to ensure devices are prepared before the old certificates expire. Without updating to the new certificates in time, systems will still boot but could stop receiving Secure Boot-related updates and become more vulnerable to boot-level threats.

This update highlights a behind-the-scenes but vital aspect of platform security: maintaining the cryptographic trust chain that ensures Windows starts securely. By proactively replacing expiring certificates via Windows Update, Microsoft is preventing what could otherwise become a systemic security and serviceability gap for millions of PCs worldwide.

AI Image Disclaimer “Visuals are created with AI tools and are not real photographs.”

Sources BleepingComputer — New Windows updates replace expiring Secure Boot certificates. Microsoft Support — Windows 10 KB5073724 update details including Secure Boot certificate logic. Microsoft Support — Secure Boot certificate expiration and update guidance. ITtrip.xyz — Practical Secure Boot certificate update guidance via Windows Update. Microsoft Tech Community — Secure Boot update deployment mechanics.

Published by Banx Network. This article is part of the Banx decentralized media programme, powered by the BXE token on the XRP Ledger.

#WindowsUpdate
Decentralized Media

Powered by the XRP Ledger & BXE Token

This article is part of the XRP Ledger decentralized media ecosystem. Become an author, publish original content, and earn rewards through the BXE token.

Newsletter

Stay ahead of the news — and win free BXE every week

Subscribe for the latest news headlines and get automatically entered into our weekly BXE token giveaway.

No spam. Unsubscribe anytime.

Share this story

Help others stay informed about crypto news

Related articles

Keep exploring the latest stories.

View more
Across China’s Digital Horizon, Embodied Intelligence Gives Artificial Intelligence a Physical Shape

Across China’s Digital Horizon, Embodied Intelligence Gives Artificial Intelligence a Physical Shape

China is accelerating embodied-intelligence development by combining AI models, robotics, sensors, and domestic computing infrastructure for physical-world app…

Listening to Residents: The Noise Pollution Debate

Listening to Residents: The Noise Pollution Debate

An environmental watchdog has challenged a giant data center project due to concerns over noise pollution, highlighting the conflict between tech growth and lo…

When Chips Become the New Industrial Currency, America Builds a Wider Road Toward Domestic Semiconductor Strength

When Chips Become the New Industrial Currency, America Builds a Wider Road Toward Domestic Semiconductor Strength

The United States is expanding semiconductor manufacturing and research capacity as AI demand increases pressure for more advanced computing infrastructure.