Skip to main content
SalesforceSecurity incident

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

What happened

Salesforce's Agentforce platform was found to have three vulnerabilities, collectively called 'SalesBleed', which could allow for zero-click CRM data theft and anonymous phishing attacks through its AI agents.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security 'SalesBleed' security flaws 'lead to very unexpected consequences' Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents' identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues. While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and when they bypass guardrails intended to limit that access. "The bigger lesson here is about what it takes to keep AI agents contained," Bargury said. "The idea of secure-by-design remains essential but for agents it may no longer be enough. We can anticipate risks and build protections into an agent from the start, yet still miss edge cases and the different ways it might behave once it encounters the real world." He added, the challenge of agent constraint is a "wider trend" that extends beyond SalesBleed. "We've seen it with the OpenAI-Hugging Face incident where the agents managed to escape the sandbox that was meant to contain them, and we're starting to see these types of flaws more and more often," Bargury...

Keep reading with a free account

The rest of this article, and every signal for Salesforce, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
Agentforce

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Three vulnerabilities, collectively called SalesBleed, allowed poisoned leads to hijack AI agents, silently steal CRM data without a click, and send phishing messages under the agents’ identities by bypassing Trusted URLs controls.

Topics and mentions

Product tags

  • online technology
  • general technology
  • future tech
  • data

Extraction

Confidence
100%
Detected
Sep 24, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Salesforce and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Salesforce this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/b1fbf6ac-c57b-d975-b4e0-9ebe0fc9cf87 returns this record as JSON. POST /v1/companies/enrich returns every signal for salesforce.com.

{
  "signal_id": "b1fbf6ac-c57b-d975-b4e0-9ebe0fc9cf87",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-24T19:01:15+00:00",
  "company": {
    "name": "Salesforce",
    "domain": "salesforce.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958",
    "title": "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing",
    "excerpt": "security 'SalesBleed' security flaws 'lead to very unexpected consequences' Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents’ identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues. While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and when they bypass guardrails intended to limit that access. “The bigger lesson here is about what it takes to keep AI agents contained,” Bargury said. “The idea of secure-by-design remains essential but for agents it may no longer be enough. We can anticipate risks and build protections into an agent from the start, yet still miss edge cases and the different ways it might behave once it encounters the real world.” He added, the challenge of agent constraint is a “wider trend” that extends beyond SalesBleed. “We’ve seen it with the OpenAI-Hugging Face incident where the agents managed to escape the sandbox that was meant to contain them, and we’re starting to see these types of flaws more and more often ,” Bargury...",
    "product": "Agentforce",
    "summary": "Salesforce's Agentforce platform was found to have three vulnerabilities, collectively called 'SalesBleed', which could allow for zero-click CRM data theft and anonymous phishing attacks through its AI agents.",
    "planning": false,
    "image_url": "https://image.theregister.com/5223048.jpg?imageId=5223048&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "product_data": {
      "name": "Agentforce",
      "full_text": "Salesforce Agentforce",
      "fuzzy_match": false
    },
    "product_tags": [
      "online_technology",
      "general_technology",
      "future_tech",
      "data"
    ],
    "published_at": "2026-09-24T19:01:15Z",
    "vulnerability": "Three vulnerabilities, collectively called SalesBleed, allowed poisoned leads to hijack AI agents, silently steal CRM data without a click, and send phishing messages under the agents’ identities by bypassing Trusted URLs controls.",
    "article_sentence": "Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents’ identities."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.