Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents’ identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues.
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
About this summary. This is a short, independently written summary of an article first published by The Register. Cyber Security News did not report or verify the underlying story. Read the original: https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958

Source attribution: headline and facts are from The Register (theregister.com). Summary method: excerpt of the source description. See our source attribution policy.






