logo

Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks

ID: de098a42-1e29-5a53-a0fb-eb8eb2db93c2

STIX ID: report--de098a42-1e29-5a53-a0fb-eb8eb2db93c2

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ashish Khaitan

...
...

**Executive summary:** A set of critical vulnerabilities in Salesforce Marketing Cloud (SFMC) — including AMPScript template injection, an unauthenticated CBC padding-oracle in the CloudPages "qs" parameter, and a weak legacy XOR-based URL format — could have allowed attackers to execute template payloads, forge cross-tenant QS tokens, and enumerate or exfiltrate subscriber records and sent email content across multiple tenants; Salesforce assigned multiple CVEs and implemented mitigations (migrated to AES-GCM, rotated keys, disabled double evaluation, and invalidated legacy links) between 21–24 January 2026, with no confirmed exploitation reported at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.