Reprimands · Online technology and telecoms
Gain Capital UK Limited
What happened
Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged an unpatched software vulnerability to access Gain Capital’s systems and exfiltrate personal data relating to 72,361 UK Data Subjects. Gain Capital had a support contract in place with a third party whom they believed were responsible for notifying Gain Capital about software security updates, however the contract stipulated that upgrades were Gain Capital’s responsibility.
Summarised from the notice published by the ICO on 10 March 2023. Read the original notice — it is the authoritative version.
The other end of this
This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.
- CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability Citrix · NetScaler
- CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability Fortinet · Multiple Products
- CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability Adobe · Commerce and Magento
- CVE-2026-86218 N-able N-central Static Code Injection Vulnerability N-able · N-central