This is a Secure Boot Playbook: https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235
I hope you will find solution there.
Secure Boot certificates out of date, no clue if upgrading is possible
I booted up today to find a yellow warning on Windows Defender. On checking it, I learned that the Secure Boot certificates "can't update due to hardware or firmware limitations." Fine. The trouble is that the page shown when I click "learn more" is entirely unhelpful, and doesn't tell me a single thing about if I, a single user and not with a business or company or anything, can do anything to fix the problem. The page indicates that there ARE updates available for people to manually install, but doesn't say anything further about where or how, and the section at the bottom about contacting Microsoft support seems to be mainly for businesses. Is this because I'm still on Windows 10 (and no, I'm not changing to 11; when this computer finally croaks, I'm switching to Linux)? I set it up for the extended support for 10, which I would think this would fall under, but maybe not. This IS a five and a half year old laptop.