ESMA Supervisory Briefing on Triangular Passporting under MiFID II
On 7 July 2026, ESMA published a supervisory briefing on triangular passporting under MiFID II, clarifying the common supervisory understanding of firms using a branch or tied agent in one host Member State to provide services in another host Member State. The briefing covers firms' responsibilities, supervisory competences, client information, and access to dispute resolution and compensation schemes.
Related updates
CSSF publishes Q2 2026 statistics on Luxembourg investment fund managers
The CSSF has published its quarterly statistics on investment fund managers, reflecting the situation as at 30 June 2026. The publication covers authorised and other investment fund managers, assets under management, investment strategies and cross-border activities, including 108 authorised IFMs represented by a branch in one or more EU Member States. The statistics are informational and introduce no new compliance obligations.
21 Sep 2026
CSSF extends LMT activation module to notifications of suspension of redemptions
On 18 September 2026, the CSSF announced that, from 21 September 2026, the activation and deactivation of a suspension of redemptions only must be notified through the CSSF eDesk “LMT activation” module. The requirement applies to Luxembourg UCIs, SIFs and SICARs within the scope of the communication. While a redemption-only suspension is not itself an LMT under the Luxembourg Law of 3 March 2026, the CSSF has integrated it into the LMT notification module. Existing administrative and documentation requirements remain unchanged. Compliance action: ensure relevant procedures and responsible teams are ready to use the eDesk module as of 21 September 2026.
18 Sep 2026
CSSF warns of active exploitation of CVE-2026-76461 in Cisco Secure Email Gateway
The CSSF has issued a communiqué alerting supervised entities to the active exploitation of CVE-2026-76461, a vulnerability in the email parsing component of Cisco AsyncOS Software for Cisco Secure Email Gateway that permits unauthenticated remote code execution with root privileges. The regulator reminds entities that such unauthorised malicious access qualifies as a major ICT-related incident requiring notification under Circular CSSF 25/893 (DORA) or CSSF 24/847, depending on entity type.
15 Sep 2026

