Comparison Overview
CBP, An Alera Group Company

CBP, An Alera Group Company
1100 Summer Street, Stamford, CT 06905, US
Last Update: 08/05/2026
National Scope. Local Service. CBP is an Alera Group firm focused on delivering customized employee benefit plans and HR technology solutions to employers of all sizes. Our solutions and services are created to uniquely fit the goals of each client, going above and bey...

Aviva
80 Fenchurch Street, London, EC3M 4AE, , GB
Last Update: 04/09/2026
💛 We're a leading Insurance, Wealth & Retirement business. 📣 Follow for #LifeAtAviva. Aviva is nothing without our people. Living up to our purpose to be with you today for a better tomorrow applies to those we work with just as much as it does to our custom...
Compliance Ranges Comparison

CBP, An Alera Group Company







Aviva






Benchmark & Cyber Underwriting Signals
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for CBP, An Alera Group Company in 2026.
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for Aviva in 2026.
Incident History - CBP, An Alera Group Company (X = Date, Y = Severity)
CBP, An Alera Group Company cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Aviva (X = Date, Y = Severity)
Aviva cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CBP, An Alera Group Company

Aviva
FAQ
Latest Global CVEs
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://mikrotik.com/supportsec/september-2026-vulnerability/
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/