Salesforce's vulnerability footprint spans a small but prominently deployed set of cloud-based customer-engagement, integration, and AI platform products that occupy a high-value position in enterprise software stacks. While the vendor's disclosed vulnerability volume remains modest in absolute terms, vulnerabilities affecting Salesforce skew strongly toward critical-severity outcomes, reflecting the trust boundary between the platform and customer data. The recurring exposure concentrates in products such as Marketing Cloud Engagement, Mule, and the Anypoint integration platform and centers on code-injection, argument-injection, XML entity-reference handling, and permission-assignment weaknesses that arise from dynamic code execution, templating, and configuration-parsing surfaces. Defenders should prioritize patching for these products given their integration depth and data-handling scope; current severity, exploitation, and product-coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Salesforce, Inc. over time
Of all the CVEs published by Salesforce, Inc. as a CNA, 33.3% affect products that Salesforce, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Salesforce, Inc., 75.0% are self-published by Salesforce, Inc. as a CNA.
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22583CRITICAL Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services | Jan 24, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22582CRITICAL Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services | Jan 24, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22586CRITICAL Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Web | Jan 24, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-22584CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This i | Jan 9, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-22585CRITICAL Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub | Jan 24, 2026 | 9.8 | 31 | NO | NO |
CVE-2023-26136CRITICAL Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. | Jul 1, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-1628CRITICAL MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affect | Mar 26, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1626CRITICAL MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions a | Mar 26, 2021 | 9.8 | 30 | NO | NO |
CVE-2016-15012CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This issue affects the function Compu | Jan 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-1627CRITICAL MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This | Mar 26, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Salesforce, Inc..
Media articles that mention a CVE ID that affects a product developed by Salesforce, Inc. — matched by CVE ID, not by vendor name.