Skip to content
Salesforce Agentforce Vulnerabilities Enable 0-Click Data Theft

Salesforce Agentforce Vulnerabilities Enable 0-Click Data Theft

First seen 24 Sep 2026, 19:56 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC

Zenity Labs disclosed three vulnerabilities in Salesforce's Agentforce, collectively termed SalesBleed, which allow attackers to exfiltrate sensitive CRM data without user interaction. The attack exploits a public Web-to-Lead form to inject malicious instructions that remain dormant until a user queries the agent. Once triggered, the agent processes the poisoned lead and executes hidden commands, leading to unauthorized data transmission to attacker-controlled servers. Salesforce has collaborated with Zenity to address these vulnerabilities by enhancing its Trusted URLs mechanism. The vulnerabilities highlight the challenges of securing AI agents and the need for continuous monitoring. The attack method involves zero-click data exfiltration and AI agent impersonation for phishing. Currently, the vulnerabilities have been patched, and the attack vectors are no longer effective.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
SalesBleed vulnerabilities disclosed
Zenity Labs revealed three vulnerabilities in Salesforce Agentforce allowing zero-click data theft and AI agent impersonation.
Morningstar
2026-09-24
Salesforce collaborates on remediation
Salesforce worked with Zenity Labs to investigate and fix the vulnerabilities, enhancing security mechanisms.
labs.zenity.io
Recent
Attack vectors patched
Salesforce implemented fixes to prevent exploitation of the identified vulnerabilities, securing the Agentforce platform.
Theregister

More articles in this cluster (6)

Following this threat?

Track Salesforce in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed