Salesforce Patched SalesBleed Security Vulnerabilities

Salesforce secured the Agentforce platform after researchers identified flaws allowing data theft and phishing.

Updated on Sept. 24, 2026 in Cybersecurity

Salesforce Patched SalesBleed Security Vulnerabilities

Live Poll

Do you trust AI agents to handle sensitive business data securely?

Salesforce has resolved three critical vulnerabilities collectively known as SalesBleed within its Agentforce AI platform. The flaws previously allowed unauthorized access to sensitive CRM data and enabled attackers to send phishing messages.

Why it matters

The vulnerabilities leveraged weak URL controls and integration gaps in Slack to bypass security protections. These security holes could have permitted attackers to exfiltrate data and manipulate AI agent communications without detection.

The SalesBleed exploit chain comprised 3 distinct vulnerabilities within the Agentforce platform. Researchers confirmed all issues were remediated by September 21, 2026.

The players

Salesforce

This global company provides a cloud-based customer relationship management platform that integrates AI tools for business operations.

Zenity Labs

This security research organization focuses on identifying risks associated with enterprise AI and automation platforms.

Slack

This messaging software platform is owned by Salesforce and provides integration points for various business applications.

The details

Attackers exploited public Web-to-Lead forms to plant indirect prompt injections that tricked AI agents into sending internal data to external servers. Additionally, flaws in Slack's URL unfurling and thread reply features allowed unauthorized data requests and automated message sending.

Timeline

  1. June 1, 2026: Zenity Labs reported the vulnerabilities to Salesforce.

  2. June 2, 2026: Salesforce confirmed it was working on fixes.

  3. August 19, 2026: Zenity confirmed the fix for URL redaction bypass.

  4. September 21, 2026: Zenity confirmed all three vulnerabilities were fixed.

  5. September 24, 2026: The Register published the report on the vulnerabilities.

The Tech Race

The emergence of AI-driven business tools has triggered a new security arms race where legacy trust models are often incompatible with autonomous agent behaviors. This incident follows a pattern where rapid platform expansion outpaces the implementation of necessary security controls.

Users of Salesforce and integrated Slack workflows should ensure their software remains fully updated to maintain the latest security protections. These patches effectively close gaps that previously left sensitive customer data exposed to external interception.

The takeaway

Enterprise AI integrations require rigorous security validation to ensure that autonomous agents do not become vectors for data exfiltration. Organizations should audit their third-party integrations and public-facing forms to prevent indirect prompt injection attacks.

Further reading

For broader trends in enterprise platform security, visit Cybersecurity.

Live Poll

Do you trust AI agents to handle sensitive business data securely?