CSSF warns of active exploitation of CVE-2026-76461 in Cisco Secure Email Gateway
The CSSF has issued a communiqué alerting supervised entities to the active exploitation of CVE-2026-76461, a vulnerability in the email parsing component of Cisco AsyncOS Software for Cisco Secure Email Gateway that permits unauthenticated remote code execution with root privileges. The regulator reminds entities that such unauthorised malicious access qualifies as a major ICT-related incident requiring notification under Circular CSSF 25/893 (DORA) or CSSF 24/847, depending on entity type.
Related updates
CSSF publishes H1 2026 profit and loss account of Luxembourg credit institutions
On 14 September 2026 the CSSF published the profit and loss account of Luxembourg credit institutions as at 30 June 2026 (available in French only). Sector profit before provisions and taxes rose 5.4% year-on-year to EUR 5,330.2 million, while net profit remained broadly in line with H1 2025 as higher allocations to provisions for risks offset the increase. The cost-to-income ratio improved marginally to 44.8% from 45.3%.
14 Sep 2026
CSSF to Modernise Prudential Reporting for PIs, EMIs and CASPs via eDesk
On 10 September 2026, the CSSF announced a project to replace the Excel-based prudential reporting process for payment institutions, electronic money institutions and CASPs authorised under Article 63 MiCAR with an integrated module in its eDesk platform. A new CSSF circular will replace Circulars CSSF 11/511 and 11/522 and introduce dedicated reporting obligations for CASPs. A testing phase runs from 1 January to 31 March 2027, with eDesk becoming the sole official submission channel from 1 April 2027.
10 Sep 2026
CSSF updates EuReCA joint controllership arrangement to reflect the establishment of AMLA
The CSSF updated its joint controllership arrangement with the EBA concerning **EuReCA**, the central database for reporting AML/CFT weaknesses, to reflect the establishment of **AMLA under Regulation (EU) 2024/1620**. The update concerns supervisory cooperation and personal-data governance and does not introduce a new direct reporting obligation for supervised entities. It nevertheless reflects the continued transition towards a more integrated EU AML/CFT supervisory framework.
11 Sep 2026

