Comparison Overview
Delta Hotels and Resorts®

Delta Hotels and Resorts®
77 King Street West, Suite 2300, Toronto, M5K 1G8, CA
Last Update: 02/02/2026
Founded in 1962 in Richmond, British Columbia, Delta Hotels and Resorts® has grown from a single 62-room motor inn to become Canada's leading first-class hotel management company. Today, we boast a diversified portfolio of 40 city-centre, airport and resort propertie...

DoubleTree by Hilton
7930 Jones Branch Drive, McLean, US
Last Update: 08/09/2026
DoubleTree by Hilton hotels are distinctively designed properties that provide true comfort to today’s business and leisure travelers. From the millions of delighted hotel guests who are welcomed with the brand’s legendary, warm chocolate chip cookies at check-in to the...
Compliance Ranges Comparison

Delta Hotels and Resorts®







DoubleTree by Hilton






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitality Industry Avg (This Year)
No incidents recorded for Delta Hotels and Resorts® in 2026.
Incidents vs Hospitality Industry Avg (This Year)
No incidents recorded for DoubleTree by Hilton in 2026.
Incident History - Delta Hotels and Resorts® (X = Date, Y = Severity)
Delta Hotels and Resorts® cyber incidents detection timeline including parent company and subsidiaries.
Incident History - DoubleTree by Hilton (X = Date, Y = Severity)
DoubleTree by Hilton cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Delta Hotels and Resorts®

DoubleTree by Hilton
FAQ
Latest Global CVEs
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-07-Unauthenticated-InstallerBypass.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/89f2916b6a46ff91bd1999ce38158fa0de8b9490
- https://github.com/krayin/laravel-crm/pull/2614
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.5
- https://vuldb.com/cve/CVE-2026-100885
- https://vuldb.com/submit/916597
- https://vuldb.com/vuln/410815
- https://vuldb.com/vuln/410815/cti
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-Attachment%20Download.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f21cdc1
- https://github.com/krayin/laravel-crm/issues/2624
- https://github.com/krayin/laravel-crm/pull/2627
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://vuldb.com/cve/CVE-2026-100884
- https://vuldb.com/submit/916218
- https://vuldb.com/vuln/410814
- https://vuldb.com/vuln/410814/cti
A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-05-Missing-Function-Level%20Authorization.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/a399404a388d8ad2700a01349d0d98069c8e85a4
- https://github.com/krayin/laravel-crm/issues/2623
- https://github.com/krayin/laravel-crm/pull/2626
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://vuldb.com/cve/CVE-2026-100883
- https://vuldb.com/submit/916128
- https://vuldb.com/vuln/410813
- https://vuldb.com/vuln/410813/cti