Comparison Overview
ISS Danmark

ISS Danmark
Gyngemose Parkvej 50, Søborg, Capital Region, DK, 2860
Last Update: 02/04/2026
Med over 40.000 kunder fordelt på mere end 30 lande verden over er ISS en af verdens førende udbydere af integrerede facility management services. 350.000 medarbejdere globalt og 6000 i Danmark er drivkraften i ISS. Sammen har de gjort ISS til det, vi er i dag – en mere...

Onet SA
36 Boulevard de l'océan, Marseille, 13009, FR
Last Update: 02/04/2026
Onet is a family service group, born in Marseille around 1860. Our 74,000 employees are spread over more than 500 locations in 8 countries. The global business volume in 2019 is 2 billion euros. Our vision: We know that human beings are never better than several people...
Compliance Ranges Comparison

ISS Danmark







Onet SA






Benchmark & Cyber Underwriting Signals
Incidents vs Facilities Services Industry Avg (This Year)
No incidents recorded for ISS Danmark in 2026.
Incidents vs Facilities Services Industry Avg (This Year)
No incidents recorded for Onet SA in 2026.
Incident History - ISS Danmark (X = Date, Y = Severity)
ISS Danmark cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Onet SA (X = Date, Y = Severity)
Onet SA cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

ISS Danmark

Onet SA
FAQ
Latest Global CVEs
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://mikrotik.com/supportsec/september-2026-vulnerability/
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/