Comparison Overview
Regus

Regus
26, Boulevard Royal, Luxembourg City, undefined, undefined, LU
Last Update: 01/04/2026
Regus provides modern, flexible workspace to customers including some of the most successful, entrepreneurs, individuals and multi-million dollar corporations. Founded in Brussels, Belgium, in 1989, Regus is based in Luxembourg and listed on the London Stock Exchange. ...

Sodexo
255 quai de la bataille de Stalingrad, 92866 Issy les Moulineaux Cedex 9, FR
Last Update: 14/09/2026
Founded in Marseille in 1966 by Pierre Bellon, Sodexo is the leader in Food and Services, shaping better everyday experiences at every moment in life: work, heal, learn and play. The Group stands out for its independence, its founding family shareholding and its respons...
Compliance Ranges Comparison

Regus







Sodexo






Benchmark & Cyber Underwriting Signals
Incidents vs Facilities Services Industry Avg (This Year)
No incidents recorded for Regus in 2026.
Incidents vs Facilities Services Industry Avg (This Year)
No incidents recorded for Sodexo in 2026.
Incident History - Regus (X = Date, Y = Severity)
Regus cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Sodexo (X = Date, Y = Severity)
Sodexo cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Regus

Sodexo
FAQ
Latest Global CVEs
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.