It would appear that the GRUB2 bootloader contained several security vulnerabilities, including BootHole which could allow a local attacker to bypass the UEFI Secure Boot.
Source: LXer – BootHole and Seven Other Vulnerabilities Patched in GRUB2, Update Your Distros Now