I am running Parallels version 26.3.3 (57507) and Windows 11 Pro 25H2. I got the same message in the Device Security panel: "Secure boot is on but your device is using an older boot trust configuration that should be updated." Today I applied the latest Windows update, KB5094126, which updated my OS build to 26200.8655. After the reboot the message in Device Security didn't change immediately. But I waited a while, and now the message has changed to "Secure Boot is on and all required certificate updates have been applied. No further certificate changes are needed." It appears that Windows has finally applied whatever updates are required to the boot manager, and combined with the updated certificates the issue appears to be resolved, at least for me.