Microsoft Ships KB5094127 ESU as Secure Boot Cert Rollover Looms

The June 2026 extended security update for Windows 10 patches Patch Tuesday bugs and adds telemetry to track the Secure Boot certificate transition.

ThreatVectr Newsdesk· 2 min read
Microsoft Ships KB5094127 ESU as Secure Boot Cert Rollover Looms
Share

Microsoft pushed KB5094127 this week, the June 2026 cumulative for Windows 10 22H2 systems enrolled in the Extended Security Updates program.

The update rolls up this month's Patch Tuesday fixes and bolts on new diagnostic plumbing to monitor the rollout of replacement Secure Boot certificates — the existing ones begin expiring this month.

That second piece is the more interesting half.

Microsoft has been warning OEMs and enterprise admins for the better part of a year that the 2011-vintage Secure Boot certificates baked into UEFI firmware are aging out. Without the new certs in the DB and KEK variables, devices will eventually stop trusting Microsoft-signed boot components, including the bootloaders shipped in future Windows updates. The company laid out the transition path in a  is still the cleanest public writeup of why this matters.

For now, the guidance is straightforward: install KB5094127 on ESU-enrolled endpoints, validate the new Secure Boot variables are landing via the new diagnostics, and watch MSRC for the per-CVE detail.

The certificate clock is already ticking.

© 2026 Threat Vectr