Unsolved

1 Rookie

 • 

45 Posts

 • 

18 Points

303

January 19th, 2026 11:05

New GPU VBIOS required before June 2026

Hi Dell and community at large.

In case you are not aware there is a potential issue with UEFI GOP firmware signing. As you may be aware, the Microsoft UEFI CA 2011 certificate which has been used to sign many NVIDIA GOP option ROMs, will expire in June 2026. With Secure Boot enabled, the motherboard's UEF firmware is going to reject expired certificates. If the GOP the card's VBIOS is signed only by the Microsoft UEFI CA 2011 certificate, the UEFI firmware will refuse to load it after expiry. This would result in =

• No pre-boot video output

• On motherboards that reauire a GPU to POST

Most Alienware systems have no iGPU fallback, the svstem may fail to boot entirely. Disabling Secure Boot is not always a practical workaround, as some software requires Secure Boot to remain enabled.

Request: To prevent these issues, I kindly ask if Dell plans to release updated VBIOS versions for affected GPUs with their GOPs re-signed using the Microsoft Option ROM UEFI CA 2023, ideally with dual signing (201 1 + 2023) for maximum compatibility.

I can see the Alienware Aurora R16 motherboard BIOS has been updated with the latest 2023 keys, but the GPU VBIOS still needs updating. Mine is a RTX 4090, but my understanding is all 40 series and older could be impacted by this.

Many thanks 

John

1 Rookie

 • 

24 Posts

January 19th, 2026 21:17

based on this Dell Article.  https://www.dell.com/support/kbdoc/en-us/000347876/microsoft-2011-secure-boot-certificate-expiration 

And a attempt to get a answer from Dell support. I am not so sure that Dell is actually doing anything  about this.   

I have also posted a question on these forums about the Secure Boot Certificate expiring. Hopefully we will both get a answer with a time line as to when they fix this.

Community Manager

 • 

1.6K Posts

 • 

6.9K Points

January 19th, 2026 22:31

As of today, there is no Dell article discussing GPU VBIOS updates.

There is no timeline for the BIOS updates.

The December 16, 2025 article discussed system models that will receive a BIOS update =

Microsoft 2011 Secure Boot Certificate Expiration

The November 21, 2025 article discussed 2019 and older models that will not receive BIOS updates with the 2023 certificate =

Microsoft 2011 Secure Boot Certificates Expiration for Out of Scope Platforms for BIOS Updates

Aurora R5 2015/R6 2016/R7 2017/R8 2018/R9 2019/R10 2019. No planned secure boot updates

This does not mean that these systems will not boot after June 2026 nor does it mean that these systems cannot get certificate updates from Windows Update. You should not reset the Secure Boot Certificates if they are updated by Windows Update as the BIOS cannot restore the new certificates.

Aurora R11 released in 2020. Periodically check the Aurora R11 Drivers & Downloads site for a BIOS update that states in the Important Information field = This BIOS contains the new 2023 Secure Boot Certificates

1 Rookie

 • 

45 Posts

 • 

18 Points

January 19th, 2026 23:22

Thanks Chris 

Hopefully there will be an update at some point with regards to the vBIOS update.

From my understanding NVIDIA 40 series cards and older (including my RTX 4090) could be impacted as their vBIOS is signed by the 2011 certificate.

10 Wizard

 • 

17.9K Posts

 • 

71.3K Points

February 20th, 2026 05:31

@John1701 ,

 

I would like to see a link or official statement on this "GPU issue" surrounding CA-2023.

 

I've just updated (as far as I can or care-to) 4 of my 8 (UEFI-class & SecureBoot-capable) computers for CA-2023. Some Dell, some MSI-motherboards (so far). Some with no more BIOS support (Aurora-R6) and some with new BIOSes containing CA-2023. Some even shipped with CA-2023's (as far back as 2022).

 

And I'll let you know later in the year (if I still having any working computers) because I have still have two GTX-1070's, one RTX-3080, and a RTX-4080 in various systems. At least 3 of those are vital (not to mention that's like $9000 worth of computers). 

 

Also, I'm not clear on why you think Intel on-board and/or on-chip GPUs are somehow excluded. That would be great for older XPS laptops with IGP. Please include link to that reference also. 

 

(edited)

1 Rookie

 • 

45 Posts

 • 

18 Points

February 20th, 2026 08:17

@Tesla1856​ 

No official article pertaining specifically to GPUs, but I can confirm my RTX 4090 does indeed contain the older 2011 certificate which expires this year in June.

A couple of pc enthusiast sites posted an article.

https://thinkcomputers.org/nvidias-older-gpus-face-potential-boot-issues-with-windows-secure-boot-in-2026/

https://www.techpowerup.com/340520/some-older-nvidia-graphics-cards-may-not-boot-correctly-with-windows-secure-boot-after-june-2026?cp=2

But wether it is a problem now the system (Alienware Aurora R16) has been updated with the new certificate remains to be seen.

10 Wizard

 • 

17.9K Posts

 • 

71.3K Points

February 20th, 2026 20:47

Thanks. I'll take a look at those.

 

If it ends-up being a problem, I'll of-course run my Intel-i9/RTX-4080 system through Origin-PC support. They are generally pretty-good.

 

My RTX-4080 is Gigabyte but the motherboard is (retail) MSI. AiO Liquid-Cooling and LEDs are Corsair-iQue . All the other parts are "retail" (but Origin-PC did the custom-build and integration) ... meaning I don't really have any "OEM parts" in our two Intel-i9 systems, AFAIK.

No Events found!

Top