Comparison Overview
CF Industries

CF Industries
2375 Waterview Dr, Northbrook, 60062, US
Last Update: 03/04/2026
At CF Industries, our mission is to provide clean energy to feed and fuel the world sustainably. The company is headquartered in Northbrook, Illinois, a suburb of Chicago. We operate manufacturing complexes in the United States, Canada, and the United Kingdom, which ar...

BASF
Carl-Bosch-Str. 38, Ludwigshafen, DE, 67056
Last Update: 13/09/2026
At BASF, we create chemistry for a sustainable future. Our ambition: We want to be the preferred chemical company to enable our customers’ green transformation. We combine economic success with environmental protection and social responsibility. Around 112,000 employees...
Compliance Ranges Comparison

CF Industries







BASF






Benchmark & Cyber Underwriting Signals
Incidents vs Chemical Manufacturing Industry Avg (This Year)
No incidents recorded for CF Industries in 2026.
Incidents vs Chemical Manufacturing Industry Avg (This Year)
BASF has 2.91% fewer incidents than the average of all companies with at least one recorded incident.
Incident History - CF Industries (X = Date, Y = Severity)
CF Industries cyber incidents detection timeline including parent company and subsidiaries.
Incident History - BASF (X = Date, Y = Severity)
BASF cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CF Industries

BASF
FAQ
Latest Global CVEs
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
- https://github.com/mistralai/mistral-vibe
- https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431
- https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553
- https://github.com/mistralai/mistral-vibe/issues/996
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5
- https://www.vulncheck.com/advisories/mistral-vibe-before-2.25.5-remote-code-execution-via-git-post-checkout