Comparison Overview
Herbalife

Herbalife
800 W Olympic Blvd, Los Angeles, CA, US, 90015
Last Update: 01/04/2026
Herbalife is a global health and wellness community born to support you in living your best life. For over 40 years and in more than 90 countries, we’ve empowered millions of people to make real changes to their lives with our science-backed products, the support of a c...

American Heart Association
7272 Greenville Ave, Dallas, 75231-4596, US
Last Update: 29/03/2026
Welcome to the American Heart Association’s movement to change the future of health and be the progress that ensures longer, healthier lives for all. By driving breakthroughs in science, policy, and care – together -- we can overcome today’s biggest health challenges a...
Compliance Ranges Comparison

Herbalife







American Heart Association






Benchmark & Cyber Underwriting Signals
Incidents vs Wellness and Fitness Services Industry Avg (This Year)
No incidents recorded for Herbalife in 2026.
Incidents vs Wellness and Fitness Services Industry Avg (This Year)
No incidents recorded for American Heart Association in 2026.
Incident History - Herbalife (X = Date, Y = Severity)
Herbalife cyber incidents detection timeline including parent company and subsidiaries.
Incident History - American Heart Association (X = Date, Y = Severity)
American Heart Association cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Herbalife

American Heart Association
FAQ
Latest Global CVEs
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.