These days, there shouldn't be too many surprises except for late stragglers.
I imagine the real wave of panic will happen not on October 13, 2026 (which is a Patch Tuesday), but November 10, 2026. That is the first Patch Tuesday where MS can drop a boot manager which can only be signed by CA 2023, since PCA 2011 has already expired. October is the last chance under the old cert to have two signed versions.
After that you're stuck with presumably disabling Secure Boot mode. Those desperate users are probably the leftovers with the unsupported BIOS'es which are more likely to get bricked because of an unseen HW limitation.