Salesforce Patched SalesBleed Security Vulnerabilities
Salesforce secured the Agentforce platform after researchers identified flaws allowing data theft and phishing.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust AI agents to handle sensitive business data securely?
Salesforce has resolved three critical vulnerabilities collectively known as SalesBleed within its Agentforce AI platform. The flaws previously allowed unauthorized access to sensitive CRM data and enabled attackers to send phishing messages.
Why it matters
The vulnerabilities leveraged weak URL controls and integration gaps in Slack to bypass security protections. These security holes could have permitted attackers to exfiltrate data and manipulate AI agent communications without detection.
The SalesBleed exploit chain comprised 3 distinct vulnerabilities within the Agentforce platform. Researchers confirmed all issues were remediated by September 21, 2026.
The players
Salesforce
This global company provides a cloud-based customer relationship management platform that integrates AI tools for business operations.
Zenity Labs
This security research organization focuses on identifying risks associated with enterprise AI and automation platforms.
Slack
This messaging software platform is owned by Salesforce and provides integration points for various business applications.
The details
Attackers exploited public Web-to-Lead forms to plant indirect prompt injections that tricked AI agents into sending internal data to external servers. Additionally, flaws in Slack's URL unfurling and thread reply features allowed unauthorized data requests and automated message sending.
Timeline
June 1, 2026: Zenity Labs reported the vulnerabilities to Salesforce.
June 2, 2026: Salesforce confirmed it was working on fixes.
August 19, 2026: Zenity confirmed the fix for URL redaction bypass.
September 21, 2026: Zenity confirmed all three vulnerabilities were fixed.
September 24, 2026: The Register published the report on the vulnerabilities.
The Tech Race
The emergence of AI-driven business tools has triggered a new security arms race where legacy trust models are often incompatible with autonomous agent behaviors. This incident follows a pattern where rapid platform expansion outpaces the implementation of necessary security controls.
Users of Salesforce and integrated Slack workflows should ensure their software remains fully updated to maintain the latest security protections. These patches effectively close gaps that previously left sensitive customer data exposed to external interception.
The takeaway
Enterprise AI integrations require rigorous security validation to ensure that autonomous agents do not become vectors for data exfiltration. Organizations should audit their third-party integrations and public-facing forms to prevent indirect prompt injection attacks.
Further reading
For broader trends in enterprise platform security, visit Cybersecurity.
Live Poll
Do you trust AI agents to handle sensitive business data securely?










