Reprimands · Central government
The Electoral Commission
What happened
Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 2022, a threat actor had access to the Electoral Commission’s systems and was able to access personal data held as part of the Electoral Register. This incident impacted approximately 40,000,000 individuals, and the initial access was gained via several unpatched software vulnerabilities. The investigation highlighted that appropriate technical and organisational measures were not in place at the time of the breach.
Summarised from the notice published by the ICO on 9 May 2024. Read the original notice — it is the authoritative version.
The other end of this
This action came down to software left unfixed. These vulnerabilities are confirmed exploited and already past their remediation deadline.
- CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability Citrix · NetScaler
- CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability Fortinet · Multiple Products
- CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
- CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability Adobe · Commerce and Magento
- CVE-2026-86218 N-able N-central Static Code Injection Vulnerability N-able · N-central