Comparison Overview
Fannie Mae Single-Family

Fannie Mae Single-Family
1501 L St NW, None, Washington, District of Columbia, US, None
Last Update: 01/11/2025
At Fannie Mae, we serve the people who house America. Our single-family business helps lenders originate mortgages in a safe and sound manner by providing a variety of financing and technology solutions. Our funding supports products such as the popular 30-year, fixed-r...

USAA
9800 Fredericksburg Rd., San Antonio, 78288, US
Last Update: 16/06/2026
Since the beginning, our mission has been to provide a range of financial services to the military community and their families. Along the way, we’ve also established ourselves as a destination employer for passionate people looking to serve those who are willing to giv...
Compliance Ranges Comparison

Fannie Mae Single-Family







USAA






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Fannie Mae Single-Family in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for USAA in 2026.
Incident History - Fannie Mae Single-Family (X = Date, Y = Severity)
Fannie Mae Single-Family cyber incidents detection timeline including parent company and subsidiaries.
Incident History - USAA (X = Date, Y = Severity)
USAA cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Fannie Mae Single-Family

USAA
FAQ
Latest Global CVEs
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI stores user account passwords in plaintext.