logo

Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk

ID: 8896137b-dbcb-57de-ae67-329f5f82a513

STIX ID: report--8896137b-dbcb-57de-ae67-329f5f82a513

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Mayura Kathir

...
...

Salesforce Marketing Cloud patched critical vulnerabilities that allowed template injection (AMPScript/SSJS) and cryptographic attacks on its email-view and CloudPages link mechanism (CBC padding-oracle and legacy XOR), enabling potential cross-tenant decryption, forging of qs tokens, and enumeration/exfiltration of subscriber records and email content; Salesforce assigned multiple CVEs, migrated to AES-GCM, rotated keys, disabled unsafe template evaluations, invalidated legacy links (21–24 Jan 2026), and reported no confirmed exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.