Comparison Overview
GOG

GOG
Jagiellońska, Warsaw, 03-301, PL
Last Update: 29/05/2026
WHO WE ARE Here at GOG we combine work with passion for gaming to offer gamers the greatest selection of Windows, Mac and Linux games, both classics and day-one titles, always DRM-free, with lots of extra goodies and amazing customer support. But GOG is more than just...

Epic Games
Cary, US
Last Update: 14/09/2026
Founded in 1991, Epic Games is a leading interactive entertainment company and provider of 3D engine technology. Epic operates Fortnite, one of the world’s largest games with over 350 million accounts and 2.5 billion friend connections. Epic also develops Unreal Engine,...
Compliance Ranges Comparison

GOG







Epic Games






Benchmark & Cyber Underwriting Signals
Incidents vs Computer Games Industry Avg (This Year)
GOG has 14.94% more incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Computer Games Industry Avg (This Year)
No incidents recorded for Epic Games in 2026.
Incident History - GOG (X = Date, Y = Severity)
GOG cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Epic Games (X = Date, Y = Severity)
Epic Games cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

GOG

Epic Games
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.