Comparison Overview
RATPgroup

RATPgroup
54 Quai de la Rapée PARIS, 75012, FR
Last Update: 01/04/2026
The RATP Group is the world's third largest public transport company, carrying 12 million people every day in France and around the world. It boasts unrivalled experience in design, project management, operation and maintenance of all types of urban and suburban transpo...

Metropolitan Transportation Authority
2 Broadway, New York, 10004, US
Last Update: 27/03/2026
The Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people in the 5,000-square-mile area fanning out from New York City through Long Island, southeastern New York State, and Connecticut. The ...
Compliance Ranges Comparison

RATPgroup







Metropolitan Transportation Authority






Benchmark & Cyber Underwriting Signals
Incidents vs Urban Transit Services Industry Avg (This Year)
No incidents recorded for RATPgroup in 2026.
Incidents vs Urban Transit Services Industry Avg (This Year)
No incidents recorded for Metropolitan Transportation Authority in 2026.
Incident History - RATPgroup (X = Date, Y = Severity)
RATPgroup cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Metropolitan Transportation Authority (X = Date, Y = Severity)
Metropolitan Transportation Authority cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

RATPgroup

Metropolitan Transportation Authority
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).