Old UEFI shim bootloaders could be abused to bypass Secure Boot on any UEFI-based machine, regardless of the operating system.

Eleven old Microsoft-signed UEFI shims could let admin-level attackers bypass Secure Boot and run code before the operating system loads

Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.