Comparison Overview
BASF Pharma Solutions

BASF Pharma Solutions
Carl-Bosch-Straße 38, Ludwigshafen am Rhein, 67056, DE
Last Update: 12/03/2026
BASF Pharma Solutions produces innovative excipients and active ingredients of outstanding quality and performance. With a global team of industry experts and digital solutions, BASF supports its customers in developing efficient, cost-effective and reliable formulation...

Novartis
Novartis Campus, Basel, 4002, CH
Last Update: 18/09/2026
Novartis is an innovative medicines company. Every day, working to reimagine medicine to improve and extend people’s lives so that patients, healthcare professionals and societies are empowered in the face of serious disease. Our medicines reach more than 250 million pe...
Compliance Ranges Comparison

BASF Pharma Solutions







Novartis






Benchmark & Cyber Underwriting Signals
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for BASF Pharma Solutions in 2026.
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
Novartis has 0.99% fewer incidents than the average of all companies with at least one recorded incident.
Incident History - BASF Pharma Solutions (X = Date, Y = Severity)
BASF Pharma Solutions cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Novartis (X = Date, Y = Severity)
Novartis cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

BASF Pharma Solutions

Novartis
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).