
Validate certificate updates
Google Cloud reminded customers that 2011 Secure Boot certificates begin expiring in June 2026 and systems without the 2023 certificates may miss future early-boot protections.
At a glance
- Existing systems should continue to start, but new boot protections and revocation updates may fail without refreshed certificates.
- The issue affects Windows and some Linux Secure Boot workflows.
Why this matters
Google Cloud reminded customers that 2011 Secure Boot certificates begin expiring in June 2026 and systems without the 2023 certificates may miss future early-boot protections.
Security teams should translate the official notice into an inventory decision, an accountable owner and documented verification rather than treating publication alone as remediation.
Who should act
- Security and technology leaders responsible for the affected platform
- Vulnerability management, cloud security and security operations teams
- Risk, compliance and service owners who track remediation evidence
SecurityTalent action checklist
- Read the linked primary source and confirm whether your products, versions, services or workflows are affected.
- Identify an accountable owner and prioritize the change according to exposure, severity and available mitigations.
- Apply the vendor guidance or compensating controls, then verify the resulting configuration or fixed version.
- Monitor the official source for revisions and preserve evidence of the assessment and remediation decision.
Source and attribution
Primary source: GCP-2026-029
- Publisher
- Google Cloud
- Author / authority
- Google Cloud Security
- Published
- May 7, 2026
- SecurityTalent review
- July 18, 2026
This is an original SecurityTalent summary and analysis based on the linked primary source. It is not a republication. The source controls if facts, versions or deadlines change after our review.