Threat · curated 24 Sep 2026

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Coverage timeline

24 Sep 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

SalesBleed shows how an indirect prompt-injection payload delivered through a public lead form can turn an enterprise AI agent into a 0-click data-theft and phishing channel, underscoring the difficulty of containing agents that bypass their guardrails.

Zenity Labs disclosed three vulnerabilities in Salesforce Agentforce, collectively named SalesBleed, that let poisoned lead-form submissions hijack the platform's AI agents to silently exfiltrate CRM data with no click required and send phishing messages under the agents' identities. Salesforce worked with Zenity to fix the flaws, and the attack chains no longer work.