Nearly 20 years of Salesforce & NetSuite expertise. Talk to an Expert →
← Back to Blog
News

Salesforce Agentforce Vulnerabilities Enabled Zero-Click Data Theft and Phishing Attacks

September 24, 2026·2 min read
EW
Erik Wiltjer
Founder, Cold Sun Enterprise
Salesforce Agentforce Vulnerabilities Enabled Zero-Click Data Theft and Phishing Attacks

Salesforce Agentforce Vulnerabilities Enabled Zero-Click Data Theft and Phishing Attacks

Salesforce Agentforce contained serious security vulnerabilities that could be exploited to compromise customer relationship management data and launch phishing attacks without requiring user interaction.

The zero-click nature of these vulnerabilities represents a significant security risk, as attackers could potentially access sensitive CRM information without victims needing to click malicious links or perform any action. This attack vector is particularly dangerous in enterprise environments where CRM systems store critical business data, customer information, and confidential communications.

The vulnerabilities also enabled threat actors to conduct anonymous phishing campaigns, potentially using compromised Agentforce instances to send fraudulent communications that appear legitimate. This capability could be leveraged to target organizations using the platform or their customers, increasing the scope of potential damage.

Agentforce, Salesforce's AI-powered agent platform, is designed to automate business processes and customer interactions. The discovery of these vulnerabilities highlights the security challenges that emerge when AI-driven automation tools are integrated into enterprise systems handling sensitive data.

The combination of zero-click exploitation and phishing capabilities creates a multi-layered threat. Attackers could silently exfiltrate data while simultaneously using the compromised system to conduct social engineering attacks against the organization or its stakeholders.

This incident underscores the importance of prompt patching and security updates for enterprise software, particularly platforms that handle sensitive business information. Organizations using Salesforce Agentforce would need to assess their exposure and implement available security patches to mitigate these risks.

The vulnerabilities serve as a reminder that cloud-based enterprise platforms require continuous security monitoring and rapid response protocols to address emerging threats in AI-driven systems.


Source Attribution

Source: The Register — Published: 2026-09-24T19:01:15.000Z

Explore More


Get Expert Advice https://www.coldsunenterprise.com/contact


Ready to Talk?

Let's discuss how Cold Sun Enterprise can help your organization get more from Salesforce and NetSuite.

Start the Conversation →