๐Ÿ” CVE Alert

CVE-2026-2298

CRITICAL 9.4
CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
8th

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.

CWE CWE-88
Vendor salesforce
Product marketing cloud engagement
Ecosystems
Industries
Enterprise
Published Mar 23, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for salesforce marketing cloud engagement

Be the first to know when new critical vulnerabilities affecting salesforce marketing cloud engagement are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Salesforce / Marketing Cloud Engagement
0 < January 30th, 2026

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.salesforce.com: https://help.salesforce.com/s/articleView?id=005299346&type=1