CVE-2026-0390 | Microsoft Windows up to Server 2022 UEFI Secure Boot reliance on untrusted inputs in a security decision
A vulnerability was found in Microsoft Windows up to Server 2022. It has been declared as critical. Impacted is an unknown function of the component UEFI Secure Boot. The manipulation results in reliance on untrusted inputs in a security decision.
This vulnerability is cataloged as CVE-2026-0390. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.