logo

Salesforce Marketing Cloud Vulnerability Opened Door to Email Data Exposure

ID: ec7ea46d-2457-542a-84ae-1e14eab5787e

STIX ID: report--ec7ea46d-2457-542a-84ae-1e14eab5787e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

Researchers discovered and reported critical vulnerabilities in Salesforce Marketing Cloud that combined template-injection flaws in AMPScript/SSJS with a weak, static XOR-based query-string encryption, enabling attackers to decrypt and forge email view links and read emails and contact data across multiple tenants; Salesforce patched the issues, issued CVEs, switched to AES-GCM, expired old links, and reported no evidence of unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.