
CVE-2026-41097 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. https://www.cve.org/CVERecord?id=CVE-2026-41097
Post summary
The post announces CVE-2026-41097, noting that an unupdateable component in Windows Secure Boot can be leveraged by an authorized attacker to bypass a local security feature.

