diff --git a/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch b/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch
index 346d0584d5..caca2955a4 100644
--- a/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch
+++ b/meta/recipes-bsp/u-boot/files/0001-Add-support-for-OpenSSL-Provider-API.patch
@@ -1,4 +1,4 @@
-From a81cb0932dce109af44d7245d47489fe54ae390f Mon Sep 17 00:00:00 2001
+From fedf11e740e7893eed6590d17e92073fcd7e7841 Mon Sep 17 00:00:00 2001
 From: Eddie Kovsky <ewk@edkovsky.org>
 Date: Mon, 23 Feb 2026 09:43:22 -0700
 Subject: [PATCH] Add support for OpenSSL Provider API
@@ -39,14 +39,14 @@ Changes from upstream:
 
 Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
 ---
- doc/build/gcc.rst      |   4 +-
- lib/aes/aes-encrypt.c |   4 +-
- lib/rsa/rsa-sign.c    | 102 +++++++++++++++++++++++++++++++++++++++---
- tools/docker/Dockerfile |  1 +
- 4 files changed, 103 insertions(+), 8 deletions(-)
+ doc/build/gcc.rst       |   4 +-
+ lib/aes/aes-encrypt.c   |   4 +-
+ lib/rsa/rsa-sign.c      | 103 ++++++++++++++++++++++++++++++++++++++--
+ tools/docker/Dockerfile |   1 +
+ 4 files changed, 104 insertions(+), 8 deletions(-)
 
 diff --git a/doc/build/gcc.rst b/doc/build/gcc.rst
-index 1fef718ceecb..29a6a632e7e3 100644
+index 1fef718ceec..29a6a632e7e 100644
 --- a/doc/build/gcc.rst
 +++ b/doc/build/gcc.rst
 @@ -25,8 +25,8 @@ Depending on the build targets further packages maybe needed
@@ -61,7 +61,7 @@ index 1fef718ceecb..29a6a632e7e3 100644
        python3-pkg-resources python3-pycryptodome python3-pyelftools \
        python3-pytest python3-pytest-xdist python3-sphinxcontrib.apidoc \
 diff --git a/lib/aes/aes-encrypt.c b/lib/aes/aes-encrypt.c
-index 90e1407b4f09..4fc4ce232478 100644
+index 90e1407b4f0..4fc4ce23247 100644
 --- a/lib/aes/aes-encrypt.c
 +++ b/lib/aes/aes-encrypt.c
 @@ -16,7 +16,9 @@
@@ -76,7 +76,7 @@ index 90e1407b4f09..4fc4ce232478 100644
  
  #if OPENSSL_VERSION_NUMBER >= 0x10000000L
 diff --git a/lib/rsa/rsa-sign.c b/lib/rsa/rsa-sign.c
-index 0e38c9e802fd..f456f3c58e65 100644
+index 0e38c9e802f..4990b43a7a6 100644
 --- a/lib/rsa/rsa-sign.c
 +++ b/lib/rsa/rsa-sign.c
 @@ -19,7 +19,47 @@
@@ -128,7 +128,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  
  static int rsa_err(const char *msg)
  {
-@@ -94,10 +134,11 @@ static int rsa_pem_get_pub_key(const char *keydir, const char *name, EVP_PKEY **
+@@ -94,10 +134,11 @@ err_cert:
   *
   * @keydir:	Key prefix
   * @name	Name of key
@@ -214,7 +214,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  	return 0;
  }
  
-@@ -226,6 +301,7 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name,
+@@ -226,6 +302,7 @@ static int rsa_pem_get_priv_key(const char *keydir, const char *name,
   * @evpp	Returns EVP_PKEY object, or NULL on failure
   * Return: 0 if ok, -ve on error (in which case *evpp will be set to NULL)
   */
@@ -222,7 +222,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  static int rsa_engine_get_priv_key(const char *keydir, const char *name,
  				   const char *keyfile,
  				   ENGINE *engine, EVP_PKEY **evpp)
-@@ -293,22 +369,25 @@ static int rsa_engine_get_priv_key(const char *keydir, const char *name,
+@@ -293,22 +370,25 @@ static int rsa_engine_get_priv_key(const char *keydir, const char *name,
  
  	return 0;
  }
@@ -249,7 +249,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  	return rsa_pem_get_priv_key(keydir, name, keyfile, evpp);
  }
  
-@@ -325,6 +404,7 @@ static int rsa_init(void)
+@@ -325,6 +405,7 @@ static int rsa_init(void)
  	return 0;
  }
  
@@ -257,7 +257,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  static int rsa_engine_init(const char *engine_id, ENGINE **pe)
  {
  	const char *key_pass;
-@@ -380,6 +460,7 @@ static void rsa_engine_remove(ENGINE *e)
+@@ -380,6 +461,7 @@ static void rsa_engine_remove(ENGINE *e)
  		ENGINE_free(e);
  	}
  }
@@ -265,7 +265,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  
  static int rsa_sign_with_key(EVP_PKEY *pkey, struct padding_algo *padding_algo,
  			     struct checksum_algo *checksum_algo,
-@@ -480,11 +561,13 @@ int rsa_sign(struct image_sign_info *info,
+@@ -480,11 +562,13 @@ int rsa_sign(struct image_sign_info *info,
  	if (ret)
  		return ret;
  
@@ -279,7 +279,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  
  	ret = rsa_get_priv_key(info->keydir, info->keyname, info->keyfile,
  			       e, &pkey);
-@@ -496,16 +579,21 @@ int rsa_sign(struct image_sign_info *info,
+@@ -496,16 +580,21 @@ int rsa_sign(struct image_sign_info *info,
  		goto err_sign;
  
  	EVP_PKEY_free(pkey);
@@ -301,7 +301,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  	return ret;
  }
  
-@@ -645,11 +733,13 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest)
+@@ -645,11 +734,13 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest)
  	ENGINE *e = NULL;
  
  	debug("%s: Getting verification data\n", __func__);
@@ -315,7 +315,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  	ret = rsa_get_pub_key(info->keydir, info->keyname, e, &pkey);
  	if (ret)
  		goto err_get_pub_key;
-@@ -726,8 +816,10 @@ int rsa_add_verify_data(struct image_sign_info *info, void *keydest)
+@@ -726,8 +817,10 @@ done:
  err_get_params:
  	EVP_PKEY_free(pkey);
  err_get_pub_key:
@@ -327,7 +327,7 @@ index 0e38c9e802fd..f456f3c58e65 100644
  	if (ret)
  		return ret;
 diff --git a/tools/docker/Dockerfile b/tools/docker/Dockerfile
-index 73bf6cdd2c52..50e98e83dc20 100644
+index ebb679a5f46..c2ccc0ca7db 100644
 --- a/tools/docker/Dockerfile
 +++ b/tools/docker/Dockerfile
 @@ -122,6 +122,7 @@ RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
diff --git a/meta/recipes-bsp/u-boot/files/0001-pylibfdt-Replace-removed-SWIG-Python-2-compatibility.patch b/meta/recipes-bsp/u-boot/files/0001-pylibfdt-Replace-removed-SWIG-Python-2-compatibility.patch
deleted file mode 100644
index c1d0204e32..0000000000
--- a/meta/recipes-bsp/u-boot/files/0001-pylibfdt-Replace-removed-SWIG-Python-2-compatibility.patch
+++ /dev/null
@@ -1,55 +0,0 @@
-From 886616d03b6afcc5ce8b34e7af91f7ccfbb0a5c Mon Sep 17 00:00:00 2001
-From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
-Date: Tue, 11 Aug 2026 13:21:01 +0000
-Subject: [PATCH] pylibfdt: Replace removed SWIG Python 2 compatibility macros
-
-SWIG 4.5.0 removed Python 2 compatibility macros (PyInt_*, PyString_*)
-from its runtime header pyhead.swg (see commit 79f7a2b7cb7d). Replace
-them with their Python 3 C API equivalents:
-
-- PyString_FromString -> PyUnicode_FromString
-- PyString_AsString -> PyBytes_AsString
-- PyInt_AsLong -> PyLong_AsLong
-
-The replacements are safe since the macros were already aliased to
-these exact functions in SWIG's Python 3 code path.
-
-This is a backport of dtc commit 5008d1d6a356 ("pylibfdt: Replace
-removed SWIG Python 2 compatibility macros").
-
-Upstream-Status: Submitted [https://patchwork.ozlabs.org/patch/2283713/]
-
-Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
----
- scripts/dtc/pylibfdt/libfdt.i_shipped | 6 +++---
- 1 file changed, 3 insertions(+), 3 deletions(-)
-
-diff --git a/scripts/dtc/pylibfdt/libfdt.i_shipped b/scripts/dtc/pylibfdt/libfdt.i_shipped
-index e4659489..326a15c7 100644
---- a/scripts/dtc/pylibfdt/libfdt.i_shipped
-+++ b/scripts/dtc/pylibfdt/libfdt.i_shipped
-@@ -1033,7 +1033,7 @@ typedef uint32_t fdt32_t;
- 	PyObject *buff;
- 
- 	if ($1) {
--		resultobj = PyString_FromString(
-+		resultobj = PyUnicode_FromString(
- 			fdt_string(fdt1, fdt32_to_cpu($1->nameoff)));
- 		buff = PyByteArray_FromStringAndSize(
- 			(const char *)($1 + 1), fdt32_to_cpu($1->len));
-@@ -1064,13 +1064,13 @@ typedef uint32_t fdt32_t;
-         }
-         $1 = PyBytes_AsString($input);
-     %#else
--        $1 = PyString_AsString($input);   /* char *str */
-+        $1 = PyBytes_AsString($input);   /* char *str */
-     %#endif
- }
- 
- /* typemaps used for fdt_next_node() */
- %typemap(in, numinputs=1) int *depth (int depth) {
--   depth = (int) PyInt_AsLong($input);
-+   depth = (int) PyLong_AsLong($input);
-    $1 = &depth;
- }
- 
diff --git a/meta/recipes-bsp/u-boot/files/0001-tools-mkeficapsule-Detect-GnuTLS-PKCS-11-support.patch b/meta/recipes-bsp/u-boot/files/0001-tools-mkeficapsule-Detect-GnuTLS-PKCS-11-support.patch
index 68865af481..e0323abef8 100644
--- a/meta/recipes-bsp/u-boot/files/0001-tools-mkeficapsule-Detect-GnuTLS-PKCS-11-support.patch
+++ b/meta/recipes-bsp/u-boot/files/0001-tools-mkeficapsule-Detect-GnuTLS-PKCS-11-support.patch
@@ -1,4 +1,4 @@
-From 007b77c2f51d4c1c696fbf1ff92694b585b35f57 Mon Sep 17 00:00:00 2001
+From 1f5b573d5340b66bf09310e8331064ca53a2d7d2 Mon Sep 17 00:00:00 2001
 From: Wojciech Dubowik <Wojciech.Dubowik@mt.com>
 Date: Tue, 9 Jun 2026 09:01:04 +0200
 Subject: [PATCH] tools: mkeficapsule: Rework pkcs11 support
@@ -22,10 +22,10 @@ Signed-off-by: Wojciech Dubowik <Wojciech.Dubowik@mt.com>
  2 files changed, 77 insertions(+), 23 deletions(-)
 
 diff --git a/tools/Makefile b/tools/Makefile
-index 1a5f425ecdaa..e85f5a354b81 100644
+index 535a5d51c89..607d6d8ff8b 100644
 --- a/tools/Makefile
 +++ b/tools/Makefile
-@@ -271,6 +271,11 @@ mkeficapsule-objs := generated/lib/uuid.o \
+@@ -272,6 +272,11 @@ mkeficapsule-objs := generated/lib/uuid.o \
  	$(LIBFDT_OBJS) \
  	mkeficapsule.o
  hostprogs-always-$(CONFIG_TOOLS_MKEFICAPSULE) += mkeficapsule
@@ -38,7 +38,7 @@ index 1a5f425ecdaa..e85f5a354b81 100644
  include tools/fwumdata_src/fwumdata.mk
  
 diff --git a/tools/mkeficapsule.c b/tools/mkeficapsule.c
-index ec640c57e8a5..c3cf48f4cc1d 100644
+index ec640c57e8a..9ac686f51a8 100644
 --- a/tools/mkeficapsule.c
 +++ b/tools/mkeficapsule.c
 @@ -207,6 +207,71 @@ static int write_capsule_file(FILE *f, void *data, size_t size, const char *msg)
@@ -175,5 +175,3 @@ index ec640c57e8a5..c3cf48f4cc1d 100644
  				gnutls_strerror(ret));
  			return -1;
  		}
--- 
-2.47.3
diff --git a/meta/recipes-bsp/u-boot/u-boot-common.inc b/meta/recipes-bsp/u-boot/u-boot-common.inc
index ece0fade55..9d217f13a5 100644
--- a/meta/recipes-bsp/u-boot/u-boot-common.inc
+++ b/meta/recipes-bsp/u-boot/u-boot-common.inc
@@ -14,7 +14,7 @@ CVE_PRODUCT = "u-boot:u-boot denx:u-boot"
 
 # We use the revision in order to avoid having to fetch it from the
 # repo during parse
-SRCREV = "ece349ade2973e220f524ce59e59711cc919263f"
+SRCREV = "5508406582f6f7120dce0c4b3059819a41788db2"
 
 SRC_URI = "git://git.u-boot-project.org/u-boot/u-boot.git;protocol=https;branch=main;tag=v${PV} \
            file://0001-pylibfdt-Replace-removed-SWIG-Python-2-compatibility.patch \
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.07.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.10.bb
similarity index 22%
rename from meta/recipes-bsp/u-boot/u-boot-tools_2026.07.bb
rename to meta/recipes-bsp/u-boot/u-boot-tools_2026.10.bb
index 9e7a178310..b28afecf72 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.07.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.10.bb
@@ -1,4 +1,6 @@
 require u-boot-common.inc
 require u-boot-tools.inc
 
-SRC_URI += "file://0001-tools-mkeficapsule-Detect-GnuTLS-PKCS-11-support.patch"
+SRC_URI += "git://git.u-boot-project.org/u-boot/u-boot.git;protocol=https;branch=main;tag=v${PV} \
+           file://0001-Add-support-for-OpenSSL-Provider-API.patch \
+           "
