Back to the blog
CVESeptember 29, 2026 5 min read

Recent Vulnerabilities and Data Exposure Trends: September 2026

Recent security disclosures highlight critical flaws in enterprise software and ongoing data breach risks, emphasizing the need for zero-knowledge security architectures.

By SecureIDsafe Threat Team · SecureIDsafe Threat Research#data-exposure

The security landscape in late September 2026 remains volatile, characterized by critical vulnerabilities in automation platforms and ongoing data exposure incidents in the healthcare sector. These events underscore the fragility of centralized trust models where a single misconfiguration or software flaw can lead to widespread unauthorized access.

What happened

DentaQuest Data Breach (September 2026)

On September 28, 2026, DentaQuest filed a notice with the Vermont Attorney General regarding a data breach [4]. The incident involved the unauthorized exposure of sensitive health records, highlighting the persistent risk to patient data within the healthcare industry [4].

EDITOR: Add specific details on the number of affected individuals if available in the public filing and describe the nature of the health records exposed.

Critical Vulnerabilities in Flowise (September 2026)

Recent security advisories identified multiple high-severity vulnerabilities in Flowise versions prior to 3.1.4. CVE-2026-91929 [HIGH 7.1] exposed cross-tenant authorization gaps, allowing attackers to delete workspaces and hijack SSO secrets [3]. Additionally, CVE-2026-91934 [HIGH 8.8] allowed for remote code execution via arbitrary file writes in the SQL Database Chain node [4].

EDITOR: Add a brief explanation of why these vulnerabilities are particularly dangerous for organizations using AI orchestration tools.

Additional Software Vulnerabilities

Other notable vulnerabilities reported recently include:

  • CVE-2026-89025 [HIGH 7.5]: A denial-of-service vulnerability in Hirschmann HiOS Switch Platform devices caused by improper HTTP(S) request validation [1].
  • CVE-2026-90650 [HIGH 7.2]: Stored Cross-Site Scripting in the MotoPress Hotel Booking plugin for WordPress, allowing unauthenticated script injection [2].
  • CVE-2026-91940 [HIGH 7.5]: An arbitrary file write vulnerability in crawl4ai before 0.9.3, enabling attackers to write malicious files to system directories [5].

Why this matters

These incidents demonstrate that the perimeter is no longer a reliable defense. Whether through a software supply chain vulnerability like those found in Flowise or a direct data breach at a healthcare provider, centralized systems are failing to protect the integrity and confidentiality of the data they store. When an attacker gains access to a server, they often gain access to everything stored in plaintext or accessible via standard service accounts.

How zero-knowledge changes this

SecureIDsafe’s zero-knowledge architecture would have neutralized these threats by ensuring that the service provider never holds the keys to the data. With AES-256 client-side encryption, even if an attacker exploited a vulnerability like the arbitrary file write in crawl4ai or the authorization bypass in Flowise, they would only encounter encrypted ciphertext. Because the device-derived keys are never transmitted to the server and recovery is managed via a non-bypassable 24-word BIP-39 seed held only by the user, the provider cannot be compelled or tricked into exposing the underlying data. In the event of a breach, the attacker would be left with useless, encrypted blobs rather than sensitive health records or SSO secrets.

Editor's checklist

  • EDITOR: Add specific details on the number of affected individuals if available in the public filing and describe the nature of the health records exposed.

  • EDITOR: Add a brief explanation of why these vulnerabilities are particularly dangerous for organizations using AI orchestration tools.

  • EDITOR: Verify the DentaQuest breach details against the latest Vermont AG filing.

  • EDITOR: Add a screenshot or diagram showing how client-side encryption prevents server-side access to data.

CVEdata-breachzero-knowledgecybersecurityvulnerability

Build your Fortress of Sovereignty.

Single users, business teams and enterprise perimeters — the same non-bypassable security, scaled to your vault.