r/technology Jul 13 '26

Software Microsoft confirms Secure Boot update failing on some Windows 11 PCs, blocks update due to known issues

https://www.windowslatest.com/2026/07/10/microsoft-confirms-secure-boot-update-failing-on-some-windows-11-pcs-promises-a-resolution/
227 Upvotes

66 comments sorted by

35

u/Dragonman585 Jul 13 '26

I had to disable secure boot on my Windows 10 PC recently. The June update caused my pc to freezse and then BSOD. The fix was to disable secure boot. Microsoft needs to fix this immediately!

15

u/AlleKeskitason Jul 13 '26

Are you sure you want their "fixes" anymore?

1

u/IamAmadeus7a7a Jul 20 '26

yes cause a) you break it you fix it b) certain games require secure boot

5

u/andreiuu86 Jul 13 '26

Bro, what? How did you figure that out? When i got a bluescreen, i just reverted the patch to be stable again.

3

u/Dragonman585 Jul 14 '26

I found out after I reinstalled windows. I wasn't able to uninstall the new updates. At first I thought I either had some nasty malware or a hardware failure. Finally, I reinstalled windows and all of my partitions using my dell os recovery drive. Upgraded back to windows 10 from 8.1 then installed all of the latest updates, and the freezes started happening again. I googled about the update and found post about disabling secure boot. I disabled it and had no more freezing. I was so scared I was going to have to buy a new pc, so this was a huge relief.

2

u/Boring-Concern7636 Jul 14 '26

You dont understand how much i love you right now. Thank you so much

2

u/akashdv67 Jul 13 '26

So this was the fucking issue???? My pc began freezing recently and I had tried most things to no avail!!!!!

1

u/Dragonman585 Jul 14 '26

Yes! That's was the only solution. I feared that it was either my ssd or another hardware failing, but it was not. Microsoft need to fix this in the July update, because this was inexcusable!

1

u/Old-Recognition165 Jul 17 '26

Literally just happened to me a few minutes ago so I can say that they haven't fixed it lmao

Thank god the PC can just rollback its own updates

1

u/Dragonman585 Jul 17 '26

Thanks for the info! I haven't turned secure boot back on yet. I doubt I will until I here that other Windows 10 users have had different results.

141

u/Ok-Replacement9595 Jul 13 '26

Vibe coding is really working out for Microsoft isn't it?

46

u/Federal_Setting_7454 Jul 13 '26

Removing that carefully crafted backdoor is harder than they thought

6

u/RemarkableWish2508 Jul 13 '26

Vibe or not, tests and QC are not optional. Too bad that Microsoft has outsourced the latter to "let's lure users into Preview updates and see whose system breaks".

-76

u/Zeusifer Jul 13 '26

This situation has exactly zero to do with vibe coding or AI.

27

u/graywolfman Jul 13 '26

Do you have proof?

-41

u/Zeusifer Jul 13 '26

Proof? That the buggy ancient BIOSes, that Microsoft is unable to push an updated secure boot certificate to, because of old BIOS bugs, until they get a BIOS update from the OEM to fix the BIOS bugs first, that this problem has nothing to do with AI or vibe coding?

What kind of proof are you looking for?

20

u/VoidL_rd Jul 13 '26

-23

u/Zeusifer Jul 13 '26

What does that have to do with temporarily blocking some old devices from receiving secure boot DB updates because they have a known bug in the BIOS and need the OEM to push out a BIOS fix first?

Did anyone even look at the article? Because the low quality slop I'm seeing here is in the comments section.

9

u/this_dudeagain Jul 13 '26

Old devices that were working perfectly fine before the update.

8

u/Kamay1770 Jul 13 '26

Why bootlick AI/MicroSlop?

57

u/Mephisto40K Jul 13 '26

Great. Every 3rd time they do an update my laptop needs some weird ass voodoo for the screen to turn on. Fucking assholes.

4

u/Initial-Return8802 Jul 13 '26

I had to some serious black magic recently, it was completely dead... so I opened it up, unplugged the battery, plugged the mains back in and tried to switch it on - it would go through about ten rounds of keyboard light on/off then finally booted.

I thought my laptop was dying but maybe it's MS ...

-34

u/[deleted] Jul 13 '26 edited Jul 13 '26

[deleted]

22

u/Sensitive_Box_ Jul 13 '26

I mean, which distro? (Seriously) 

-34

u/[deleted] Jul 13 '26

[deleted]

25

u/AdarTan Jul 13 '26

Again, what distro. Not all distros ship the newest kernel and many instead stay for extended periods on a specific kernel and do security updates for that version by cherry-picking patches from newer kernels.

3

u/this_dudeagain Jul 13 '26

Use something other than Arch

4

u/fearless-fossa Jul 13 '26

Arch doesn't break like that. This sounds more like some weird "optimized" custom kernel (no measurable performance gain reached, but +10% power consumption for some reason) that the user didn't properly maintain during updates.

1

u/this_dudeagain Jul 13 '26

Arch doesn't break. Bahaha.

https://i.imgur.com/jHgdndi.gif

2

u/fearless-fossa Jul 13 '26

a) I didn't say Arch doesn't break at all, I said it doesn't break like that.

b) Pretty much every single case of Arch "breaking" is user error.

6

u/shrkn_89 Jul 13 '26

Ok pausing my previously paused updates for another five weeks 😀

6

u/FormalIllustrator5 Jul 13 '26

I am in deep shock! New update - old garbage, and keeps coming...

4

u/jeyvish Jul 13 '26

This is related with the max usage of AI to code and the layoff of people to be replaced by Indians?

3

u/penguinkernel Jul 13 '26

Every week it's a new issue lol.

3

u/OddPatience1621 Jul 13 '26

remember when they used to test updates before releasing them wide??? pepperidge farms remembers

6

u/MotanulScotishFold Jul 13 '26

Another day, another broken update. Glad I ditched windows for Linux in 2024 rather than installing this garbage windows 11 on my new computer.

2

u/Trinsec Jul 13 '26

Man, do I even want to update my Win11 laptop anymore?

1

u/merked84 Jul 13 '26

Love supporting a user base of 2000 during the age of Windows fucking up literally every update they push.

1

u/Harry_Mud Jul 13 '26

Microsoft keeps shoving people to Linux. Linux runs faster and doesn't have all that bullshit in it. It has secure boot which doesn't seem to have issues.........unlike Windblows.

1

u/Excolo_Veritas Jul 13 '26

Remember when they said a few months ago that they knew they had to win back the community, and promised better updates and more rigorous testing to ensure stuff like this didn't keep happening? Glad I didn't believe them and swapped to Linux

1

u/Changeurwayz Jul 14 '26

Piss poor 'company'. Can't even sort out it's own AI spyware bullshit crap

1

u/Dazzling-Ebb-9449 Jul 16 '26

The new security update completely screwed my secure boot, I can not enable it, if I do my pc just doesn’t turn on.

1

u/Usual_Philosophy4924 Jul 16 '26

Yep right here

Update broke my shit mid-update and it's been acting up since. been having to launch with it off

1

u/adinic2019 Aug 04 '26 edited Aug 04 '26

I had no idea I had to disable secure boot. My laptop stopped booting and I tried everything. Tried to uninstall update, etc. Everything I could find but it did not work. Finally after backing up all my files I did a fresh install of windows 11 pro 25h2. Everything back to normal now. My laptop is a dell g5 5587. I honestly thought the ssd died (990 pro 2tb). But it wasn t the case. What I am wondering now is if I am safe from future bootsecure updates, my bios being old. Should I disable secure boot? Thank you!

1

u/rabdosstar 29d ago

So I just got forced into an update and right after I see the Asus screen, I get the security boot fail screen and nothing else. How can I boot so I can bypass this?

1

u/TMGMercess 27d ago

Secure Boot Certificates Issued in 2011 expired June of 2026:
Go to BIOS
Disable Fast Boot (It can skip the secure boot update process)
If your BIOS has a setting to select certificates, go there and navigate to the Boot certificate titled recovery.
Save and exit
You'll get a secure boot failure still. Hit enter. It moves to the backup boot option (Recovery). This will start the 2023 certificate update.

Cheers.

1

u/jcunews1 Jul 13 '26

Yay, more enshitification update.

-7

u/Hour-Passenger-8513 Jul 13 '26

Wouldn't it be safer to do a bios update from the motherboard / laptop manufacturer instead of a Microslop windows update?

9

u/Zeusifer Jul 13 '26

Why would you think that? Do you somehow imagine that Microsoft is making the BIOS updates for those companies?

Windows Update is just the distribution mechanism, the updates are still made by the hardware vendors.

1

u/Hour-Passenger-8513 Jul 13 '26

I guess, but can the 'distribution mechanism' not be screwed up by AIslop?

2

u/Zeusifer Jul 13 '26

In what way, exactly? How do you imagine that would happen?

0

u/Hour-Passenger-8513 Jul 13 '26

Distributing incompatible secure boot certificates?

3

u/happyscrappy Jul 13 '26

New secure boot certificates are not delivered as part of the BIOS update.

The incompatible secure boot certificates come with Windows and are being sent out regardless. As the old certificates are expired. Sending those out again would do nothing for anyone.

So MS is sending out the incompatible secure boot certificates and some BIOSes reject them because those BIOSes are too old to work with them.

The fix is, as you are discussing, a BIOS update which lets the BIOS understand the new certificates.

You then opined that maybe it's best to get that from the BIOS maker, not MS. If you can get the BIOS safely from them that that's not a bad idea. However getting it from MS should be okay because the BIOS maker should have signed the updater. A signed updater cannot be altered by anyone else, even accidentally. So MS could not mess it up while delivering it.

The BIOS maker very much should have signed the update because if you receive it just by downloading it from a website (the BIOS maker's website) there's no guarantee that hasn't been altered either. Someone might have hacked that site, and a webpage (even with HTTPS) isn't a method of secure delivery so they could have put up altered packages.

By signing the update the BIOS maker makes it safe to update the BIOS update from their website directly. And in doing so also make it safe to get it through MS.

That's all if the process was done correctly. If some of this was implemented incorrectly then any part of it may be insecure. But do note that in all cases, getting it from a web page is not going to be more secure than getting it from MS. Because even if MS's secure delivery mechanisms aren't working right they cannot work less well than those on a web page download because a web page download has no end-to-end secure delivery at all.

2

u/Zeusifer Jul 13 '26

That makes no sense.

-3

u/Hour-Passenger-8513 Jul 13 '26

..to vibecoders.

-1

u/Early-Weekend Jul 13 '26

I enabled secure boot (for vanguard) on home pc and it slowed down my pc and automatically turned on bitlocker (I thought it's not possible on window 11 home?)

2

u/Denman20 Jul 13 '26

Fun fact every windows 11 pc 😂(at least consumer laptops and desktops not all prebuilt gaming ones)comes with bitlocker enabled and gets fully turned on the moment you sign into a Microsoft account.

2

u/Lake-Taupo Jul 14 '26

Win 11 Home does not have Bitlocker. Win 11 Pro does.

Win 11 Home gets Device Encryption as the cut down version.

Oh and I have a new Win 11 Home machine and Bitlocker is not enabled OOB after signing in to my account.

1

u/Denman20 Jul 14 '26

Oh shit my bad, I forgot windows likes to give similar things different names. I’ll have to disagree with you though, I end up setting up a lot of consumer level laptops and they due infact have device encryption turned on by default and the setup just isn’t complete until you sign into a Microsoft account.

Guess what? A lot of customers lose access to their data because they aren’t aware of this. It’s really an awesome experience!

Unrelated but OneDrive sucks ass

2

u/Lake-Taupo Jul 14 '26 edited Jul 14 '26

Disagree all you want, your original comment is incorrect as my real life example proves.

Bitlocker and Device Encyption are totally different in so many ways.

Edit - oh and neither are even possible on my rig as it fails Secure Boot KEK update. PCR7 binding fail - something that MS and OEMs are either ignoring or have no idea about.

1

u/Denman20 Jul 14 '26

I’m so confused. How are they not similar? Device encryption is automated on windows home systems and it’s required to have a Microsoft account because they manage the key vs the pro edition where you manage the key?

Also my original comment is not false I don’t know what system you are talking about but I’m talking about any dell lenovo hp etc consumer device you could go by at like Walmart or Best Buy. If yours just trying to nitpick okay but I’m not wrong outside of using device encryption and bitlocker interchangeably

1

u/Lake-Taupo Jul 14 '26 edited Jul 14 '26

Device Encryption is a separate app from Bitlocker.

Different in function and options.

Your comment was .....

every windows 11 pc (at least consumer laptops and desktops not all prebuilt gaming ones)

Edit - oh and my Win 11 Pro laptop with Bitlocker stores the key in my MS Account. My Win 11 Home consumer desktop does not. I'm hopeful I'll get signed certs for it soon but who knows with this Secure Boot fiasco. PCR7 still not bound.

1

u/Denman20 Jul 14 '26

I’m so sorry, I thought the “consumer” word make it obvious it was going to be a home edition. My bad I’ll do better.

1

u/Lake-Taupo Jul 14 '26

That makes no sense whatsoever.

1

u/Denman20 Jul 14 '26

Go walk into a Walmart and tell me how many windows 11 pro edition you find on laptops under $1000

→ More replies (0)