CSSF: Luxembourg UCI Net Assets Reach €6.73 Trillion at End June 2026
The CSSF has published its monthly statistical release on Luxembourg undertakings for collective investment (UCIs) as at 30 June 2026. Total net assets reached €6,731.325 billion, up 1.46% over the month and 16.31% year-on-year. The increase reflects positive net capital investment (+€23.846 billion) and favourable market developments (+€73.086 billion).
Related updates
CSSF publishes Q2 2026 statistics on Luxembourg investment fund managers
The CSSF has published its quarterly statistics on investment fund managers, reflecting the situation as at 30 June 2026. The publication covers authorised and other investment fund managers, assets under management, investment strategies and cross-border activities, including 108 authorised IFMs represented by a branch in one or more EU Member States. The statistics are informational and introduce no new compliance obligations.
21 Sep 2026
CSSF extends LMT activation module to notifications of suspension of redemptions
On 18 September 2026, the CSSF announced that, from 21 September 2026, the activation and deactivation of a suspension of redemptions only must be notified through the CSSF eDesk “LMT activation” module. The requirement applies to Luxembourg UCIs, SIFs and SICARs within the scope of the communication. While a redemption-only suspension is not itself an LMT under the Luxembourg Law of 3 March 2026, the CSSF has integrated it into the LMT notification module. Existing administrative and documentation requirements remain unchanged. Compliance action: ensure relevant procedures and responsible teams are ready to use the eDesk module as of 21 September 2026.
18 Sep 2026
CSSF warns of active exploitation of CVE-2026-76461 in Cisco Secure Email Gateway
The CSSF has issued a communiqué alerting supervised entities to the active exploitation of CVE-2026-76461, a vulnerability in the email parsing component of Cisco AsyncOS Software for Cisco Secure Email Gateway that permits unauthenticated remote code execution with root privileges. The regulator reminds entities that such unauthorised malicious access qualifies as a major ICT-related incident requiring notification under Circular CSSF 25/893 (DORA) or CSSF 24/847, depending on entity type.
15 Sep 2026

