INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Salesforce Agentforce Vulnerabilities Expose Wider AI-Driven Data Theft Risk
| 2026-09-25 09:27 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A recent incident involving the use of untrusted CRM content to turn AI agents into data-exfiltration paths has been identified, with a specific vulnerability in Salesforce's Agentforce product being exploited. The attack chain combined prompt injection via Web-to-Lead forms, agent trusting record content as instructions, and underlying access to sensitive tool and data permissions. This allowed the injected payload to instruct the agent to quietly query and exfiltrate sensitive account data using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls. The incident highlights a latent risk pattern not unique to Agentforce, with any AI agent reading or processing records from external sources rendering links, images, or other rich content back to users holding tool access to sensitive backend data creating the same three ingredients for prompt injection-driven exfiltration. This vulnerability was reported by Zenity in June and fully remediated on August 18, but its implications underscore a broader risk within the legal sector using Roundcube infrastructure.
Technical Mitigations AI-generated
• Implement URL redaction controls to prevent data leakage through outbound links.
• Validate and sanitize external input before processing it by the AI agent, preventing prompt injection payloads from being executed.
• Limit access to sensitive tool and data permissions for AI agents, reducing their ability to exfiltrate sensitive information.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
June 1
The cybersecurity firm reported the SalesBleed vulnerabilities in Salesforce on June 1.
August 18
Salesforce fully fixed the URL redaction bypass vulnerabilities reported by Zenity in June, remediating the 'SalesBleed' flaws that enabled zero-click data exfiltration.
Click on any entity below to view its context and source!
organisation
Salesforce
Zenity reported the vulnerabilities to Salesforce in June, and Salesforce fully fixed the URL redaction bypass, which remediated the issues, on August 18.
August 19
Salesforce confirmed that all three identified 'SalesBleed' vulnerabilities had been addressed by August 19.
September 24by
Threat actors exploited vulnerabilities in Salesforce Agentforce, a zero-click data exfiltration tool, to target organizations using the platform.
2026/09/25
Threat actors exploited vulnerabilities in Salesforce Agentforce, specifically through Web-to-Lead forms and interactions with Slack, to enable zero-click data exfiltration and phishing attacks.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Related:
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Related:
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Related:
AI-Powered Campaign Targets Hundreds of Online Retailers
Related:
organisation
Zero-Click Data Exfiltration
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration.
organisation
SalesBleed
According to Zenity Labs, two of the SalesBleed bugs could be exploited in zero-click data exfiltration attacks, while the third allowed attackers to weaponize an Agentforce agent to distribute phishing messages.
Untrusted CRM Content Can Turn AI Agents Into Data-Exfiltration Paths
While the specific vulnerabilities in SalesBleed have been fixed, the Zenity researchers emphasized that the underlying risk pattern is not unique to Agentforce.
organisation
HTML
Zenity Labs discovered that a Web-to-Lead form payload could be used to access leads and accounts table data and then use HTML image tags for zero-click CRM data exfiltration to the attacker’s server.
organisation
DNS
…ve tool and data permissions
Once triggered, the injected payload could instruct the agent to quietly query and exfiltrate sensitive account data, including company names, deal sizes and other CRM fields, using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls, a safeguard designed to prevent exactly this kind of data leakage through outbound links.
organisation
Salesforce
Dubbed
SalesBleed
, the flaws could be exploited via Web-to-Lead forms, Salesforce’s official lead-collection mechanism, which also provides a direct path to the CRM.
organisation
Agentforce
Malicious instructions injected into a Web-to-Lead lead would remain dormant until an employee asks an Agentforce agent to interact with the submission, causing the agent to process the poisoned lead and execute the hidden instructions.
When an Agentforce agent later processed that record as part of normal business operations, the embedded instructions would hijack the agent's behavior.
organisation
Agentforce-Slack
The third affects the Agentforce-Slack integration.
organisation
Slack
Using the same poisoned Web-to-Lead mechanism, an attacker could interact with the Agentforce agent via Slack, which automatically retrieves link information for previews.
organisation
Trusted
We’ve also strengthened Trusted URLs over the past year through deeper integration into core Agentforce components.
organisation
Zero-Click
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk.
organisation
Query Records
“Our payload asked for company names and deal sizes, but the injection could have asked for anything the subagent's Query Records tool can reach (which can include sensitive data).
organisation
Shutterstock.com
Image credits: bluestork /JHVEPhoto / Shutterstock.com
Tactical Metrics
Metrics
infrastructure
Roundcube
Affected Product
Click for context!
Related:
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Related:
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Related:
AI-Powered Campaign Targets Hundreds of Online Retailers
Related:
Intelligence Sources
Infosecurity-Magazine
2026-09-25
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Infosecurity-Magazine
SecurityWeek
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:36
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Zero-Click Data Exfiltration
entity
4x
timeline
Temporal Reference
June 1
date
2x
tactic
Cyber Operation Type
Exfiltration
tactic
Contextual Telemetry
Context Block
3 METRICS
industry
Targeted Sector
Legal
sector
infrastructure
Affected Product
Roundcube
software
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.