๐Ÿ” CVE Alert

CVE-2026-22586

CRITICAL 9.8
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

CWE CWE-321
Vendor salesforce
Product marketing cloud engagement
Ecosystems
Industries
Enterprise
Published Jan 24, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for salesforce marketing cloud engagement

Be the first to know when new critical vulnerabilities affecting salesforce marketing cloud engagement are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Salesforce / Marketing Cloud Engagement
0 < January 21, 2026

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.salesforce.com: https://help.salesforce.com/s/articleView?id=005299346&type=1