← Back to news
The Register - Security24 Sept 2026 · 1 min read

Reported Agentforce Flaws Raised Concerns Over CRM Data Exposure and Phishing Abuse

Security concerns have been raised over reported vulnerabilities in Salesforce Agentforce that could potentially have enabled unauthorized access to customer relationship management data and supported...

Security concerns have been raised over reported vulnerabilities in Salesforce Agentforce that could potentially have enabled unauthorized access to customer relationship management data and supported phishing activity without requiring attackers to identify themselves.

The limited information available describes the issues as “zero-click,” a term generally used for flaws that can be exploited without a victim needing to open a link, download a file, or take another direct action. If confirmed, such weaknesses could be especially significant in CRM environments, where systems may contain customer records, sales information, support cases, and internal business data.

Potential impact

The reported issues could have created two broad risks: exposure of CRM information and abuse of trusted business platforms for phishing. Unauthorized access to CRM data can give attackers material for highly convincing social-engineering campaigns, including messages tailored with customer names, account details, or active business conversations.

Anonymous phishing capabilities could also make attribution and abuse prevention more difficult, particularly if attackers can use platform-connected workflows or communications features without adequate identity verification or monitoring.

What organizations should review

  • Confirm that Salesforce products, integrations, and Agentforce-related components are running supported and current versions.
  • Review access controls, guest permissions, API exposure, and third-party connections that can reach CRM data.
  • Monitor for unusual automated activity, unexpected data exports, and suspicious outbound communications.
  • Train employees and customers to validate unexpected requests, even when messages appear to reference legitimate account information.
  • Follow Salesforce security advisories and apply any vendor-recommended mitigations promptly.

No technical details, affected versions, discovery timeline, or information about patches were included in the supplied report. Organizations should therefore rely on official Salesforce advisories and validated security research when assessing whether their deployments are affected.

Share this article:TwitterLinkedIn