Salesforce Fixes SalesBleed: 3 Agentforce AI Flaws [2026]

3 days ago
1 min read
Salesforce has quietly patched a set of AI agent flaws that let attackers pull customer data out of live CRM systems without a single click from a victim. Zenity Labs, an AI agent security research firm, disclosed the vulnerabilities on September 24, 2026, under the name “SalesBleed,” according to Infosecurity Magazine. The flaws lived inside Agentforce, the AI agent platform Salesforce has pushed hard into its customer base since 2025, and they worked by hiding malicious instructions inside something as mundane as a public contact form.
Comments