Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks
ID: de098a42-1e29-5a53-a0fb-eb8eb2db93c2
STIX ID: report--de098a42-1e29-5a53-a0fb-eb8eb2db93c2
Feed Name: The Cyber Express
**Executive summary:** A set of critical vulnerabilities in Salesforce Marketing Cloud (SFMC) — including AMPScript template injection, an unauthenticated CBC padding-oracle in the CloudPages "qs" parameter, and a weak legacy XOR-based URL format — could have allowed attackers to execute template payloads, forge cross-tenant QS tokens, and enumerate or exfiltrate subscriber records and sent email content across multiple tenants; Salesforce assigned multiple CVEs and implemented mitigations (migrated to AES-GCM, rotated keys, disabled double evaluation, and invalidated legacy links) between 21–24 January 2026, with no confirmed exploitation reported at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
