Comparison Overview
GOG

GOG
Jagiellońska, Warsaw, 03-301, PL
Last Update: 29/05/2026
WHO WE ARE Here at GOG we combine work with passion for gaming to offer gamers the greatest selection of Windows, Mac and Linux games, both classics and day-one titles, always DRM-free, with lots of extra goodies and amazing customer support. But GOG is more than just...

Ubisoft
2, Avenue Pasteur, Saint-Mandé, 94160, FR
Last Update: 13/09/2026
Ubisoft is a global leader in gaming with teams across the world crafting original and memorable gaming experiences featuring brands such as Assassin’s Creed®, Brawlhalla®, For Honor®, Far Cry®, Tom Clancy’s Ghost Recon®, Just Dance®, Rabbids®, Tom Clancy’s Rainbow Six®...
Compliance Ranges Comparison

GOG







Ubisoft






Benchmark & Cyber Underwriting Signals
Incidents vs Computer Games Industry Avg (This Year)
GOG has 14.94% more incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Computer Games Industry Avg (This Year)
No incidents recorded for Ubisoft in 2026.
Incident History - GOG (X = Date, Y = Severity)
GOG cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Ubisoft (X = Date, Y = Severity)
Ubisoft cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

GOG

Ubisoft
FAQ
Latest Global CVEs
HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.