Security firm Zenity Labs disclosed SalesBleed vulnerabilities that allowed zero-click CRM data leaks.
Cybersecurity firm Zenity Labs disclosed on September 24, 2026, a set of three vulnerabilities in Salesforce Agentforce dubbed SalesBleed. The flaws allowed attackers to silently extract sensitive CRM records without user interaction and use internal enterprise agents to distribute phishing messages.
The research showed that malicious instructions planted in standard Web-to-Lead forms could compromise Agentforce agents when an employee later reviewed the lead. Two zero-click vulnerabilities bypassed Salesforce's Trusted URLs controls through image requests and Slack link unfurling, sending CRM data such as deal sizes, contracts, pricing, and contact details to external attacker servers. A third flaw in the Agentforce-Slack integration allowed attackers or malicious insiders to send phishing messages under the trusted agent's identity.
Zenity Labs reported the issues to Salesforce on June 1, 2026. Salesforce worked directly with the researchers and remediated the specific Trusted URLs bypasses within approximately two weeks, while also addressing the Slack agent attribution flaw.
Newsletter
Markets in your inbox, weekly
Latin America-focused analysis, investment themes and the week in finance.