That's a fixed bug. Download the ZIP file again.
I downloaded the new ZIP file. This looks good, I think:
I also ran the latest Check-UEFI.bat -Verbose which also looks good, I think. What say you
@garlin ? Now I'll have to try to remember how to update my Macrium X Rescue boot USB. Then I'll have to wait for my wife to get off her desktop so I can do all of this on her machine.... groan
Windows 11 25H2 (26200.9445)
Secure Boot: ON
Virtualization Based Security: ON
BitLocker on (C:) OFF
BIOS Firmware
-------------
LENOVO 20N20028US
Version: N2IETA7W (1.85 )
Date: 2026-04-06
Factory Default UEFI PK Cert
----------------------------
Lenovo Ltd. PK CA 2012
UEFI PK Cert
------------
Lenovo Ltd. PK CA 2012
Factory Default UEFI KEK Certs
------------------------------
Microsoft Corporation KEK CA 2011
Lenovo Ltd. KEK CA 2012
Microsoft Corporation KEK 2K CA 2023
UEFI KEK Certs
--------------
Microsoft Corporation KEK CA 2011
Lenovo Ltd. KEK CA 2012
Microsoft Corporation KEK 2K CA 2023
Factory Default UEFI DB Certs
-----------------------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ThinkPad Product CA 2012
Lenovo UEFI CA 2014
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
UEFI DB Certs
-------------
Microsoft Corporation UEFI CA 2011
Microsoft Windows Production PCA 2011
ThinkPad Product CA 2012
Lenovo UEFI CA 2014
Microsoft Option ROM UEFI CA 2023
Microsoft UEFI CA 2023
Windows UEFI CA 2023
Factory Default UEFI DBX Certs
------------------------------
Debian Secure Boot Signer
Canonical Ltd. Secure Boot Signing
EFI_CERT_SHA256_GUID Signatures: 894
UEFI DBX Certs
--------------
Microsoft Windows Production PCA 2011
Windows BootMgr SVN 11.0
EFI_CERT_SHA256_GUID Signatures: 506
UEFI Variables
--------------
Credential Guard: ON
SBAT (Linux only): sbat,1,2025051000 / shim,4 / grub,5 / grub.debian,4 / grub.peimage,2 / grub.proxmox,2
EFI Files
---------
Windows Boot Manager [Windows UEFI CA 2023] is ALLOWED.
\\.\HarddiskVolume2\EFI\Microsoft\Boot\bootmgfw.efi
File Version: 28000.367, SVN 11.0
Registry: "WindowsUEFICA2023Capable" = 2
[Windows UEFI CA 2023] in UEFI DB, and Windows starting from CA 2023 Boot Manager.
[OPTIONAL] SkuSiPolicy.p7b (for VBS) is MISSING.
STATUS REPORT
-------------
Registry: "UEFICA2023Status" = Updated
SUCCESS: UPDATES ARE FINISHED.
UEFI CA 2023 certs are present, PCA 2011 cert is revoked.
PS C:\SecureBoot\SecureBoot-CA-2023-Updates_v2026-09-10>