Threat · curated 24 Sep 2026
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
First reported theregister.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
SalesBleed shows how an indirect prompt-injection payload delivered through a public lead form can turn an enterprise AI agent into a 0-click data-theft and phishing channel, underscoring the difficulty of containing agents that bypass their guardrails.
Zenity Labs disclosed three vulnerabilities in Salesforce Agentforce, collectively named SalesBleed, that let poisoned lead-form submissions hijack the platform's AI agents to silently exfiltrate CRM data with no click required and send phishing messages under the agents' identities. Salesforce worked with Zenity to fix the flaws, and the attack chains no longer work.