SalesBleed (Zenity): Salesforce Agentforce Trusted URLs / Slack — zero-click CRM exfil + agent phishing (fixed 19 Aug)
Zenity Labs (SecurityWeek 25 September 2026) disclosed three Salesforce Agentforce flaws dubbed SalesBleed, exploitable via poisoned Web-to-Lead submissions that stay dormant until an employee asks an Agentforce agent to handle the lead. Two bugs abused Trusted URLs weaknesses (including TLD/URL-parsing gaps) so HTML image tags could zero-click exfiltrate leads/accounts CRM data to attacker infrastructure while the UI still reported content blocked; the third abused Agentforce–Slack integration so the trusted agent identity could post phishing messages to internal channels (Slack link-preview requests likewise carried CRM data). Zenity reported 1 June 2026; Salesforce confirmed all three addressed by 19 August 2026. No CVE IDs or CVSS published in the wire write-up — do not invent scores. Primary wire: SecurityWeek; research: Zenity (primary research URL degraded/500 during this pass).
- Product
- Salesforce Agentforce (Trusted URLs; Agentforce–Slack integration; Web-to-Lead)
- Versions
- Flaws reported 1 Jun 2026; Salesforce confirmed remediated by 19 Aug 2026 per Zenity/SecurityWeek. Confirm Agentforce orgs received the August platform fixes; review Trusted URLs allowlists and Slack agent posting scopes.
- Exploited in Australia?
- unknown
- Patch to
- Confirm Salesforce August Agentforce fixes are live on your org; tighten Web-to-Lead intake and Agentforce Trusted URLs; restrict agent Slack posting; hunt for anomalous agent-originated Slack messages and unexpected outbound image/beacon requests from CRM context.
Primary: SecurityWeek — SalesBleed / Agentforce zero-click exfil (25 Sep 2026) · Vendor: Salesforce Security (vendor security hub) · Cyber Security News — Salesforce Agentforce amplify (25 Sep 2026)
