Root cause
Unpatched or unsupported software
A known vulnerability was left unfixed, or the software was past end of support. The most directly preventable cause on this list.
3
UK enforcement actions
£0
in penalties
3
sectors affected
The vulnerabilities behind this
Confirmed exploited in the wild and already past their remediation deadline — the definition of the failure the ICO keeps fining people for.
- CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability Citrix · NetScaler
- CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability Fortinet · Multiple Products
- CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability Adobe · Commerce and Magento
- CVE-2026-86218 N-able N-central Static Code Injection Vulnerability N-able · N-central
- CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability Kestra · Kestra OSS
- CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability JFrog · Artifactory
- CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability Sangoma · Switchvox
- CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability SonicWall · SMA1000 Appliances
- CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability SonicWall · SMA1000 Appliances
Where it happens
- Central government1
- Online technology and telecoms1
- Charitable and voluntary1
Every case
- The Electoral Commission Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 20…
- Gain Capital UK Limited Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged a…
- Chartered Institute for Securities & Investment An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a…