Proxmox VE 9 requires targeted hardening of the boot chain, package sources, and SSH access to reduce the extended attack surface inherent to the architecture.
Nearly a dozen vulnerable UEFI Shim bootloaders remained trusted for years because revocation mechanisms were not updated in a timely manner, creating a direct path to bypassing Secure Boot.
Secure Boot certificates from 2011 expired on June 24, 2026; more will expire in October – updates to 2023 certificates fail on some devices, and Microsoft now provides error documentation.
Secure Boot certificates will expire on 24 June 2026 for Windows and Linux systems with Secure Boot enabled, requiring administrators to plan timely rollout of new certificates.
Replacement of outdated Secure Boot certificates is necessary by June 2026 to prevent systems from losing the ability to verify new bootloaders and deploy security updates.
After Secure Boot certificates expire in 2026, systems will no longer be able to verify new 2023-signed bootloaders and will not receive security updates against pre-boot attacks.