Comparison Overview
Ulta Beauty

Ulta Beauty
1000 Remington Blvd, Bolingbrook, 60440, US
Last Update: 02/04/2026
At Ulta Beauty (NASDAQ: ULTA), the possibilities are beautiful. Ulta Beauty is the largest U.S. beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products and salon services. In 1990, the Company reinvented the be...

Hy-Vee, Inc.
5820 Westown Parkway, West Des Moines, 50266, US
Last Update: 02/04/2026
Hy-Vee, Inc. is an employee-owned corporation operating more than 563 business units across nine Midwestern states with sales of more than $13 billion annually. The supermarket chain is synonymous with quality, variety, convenience, healthy lifestyles, culinary expertis...
Compliance Ranges Comparison

Ulta Beauty







Hy-Vee, Inc.






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Ulta Beauty in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Hy-Vee, Inc. in 2026.
Incident History - Ulta Beauty (X = Date, Y = Severity)
Ulta Beauty cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Hy-Vee, Inc. (X = Date, Y = Severity)
Hy-Vee, Inc. cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Ulta Beauty

Hy-Vee, Inc.
FAQ
Latest Global CVEs
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.