CVE-2026-22585: Critical severity Salesforce Marketing Cloud Engagement vulnerability
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22585?
CVE-2026-22585 is classified as a moderate severity vulnerability due to the potential for web services protocol manipulation.
How do I fix CVE-2026-22585?
To remediate CVE-2026-22585, ensure that you are using updated versions of Salesforce Marketing Cloud Engagement addressing the cryptographic algorithm weaknesses.
What versions of Salesforce Marketing Cloud Engagement are affected by CVE-2026-22585?
CVE-2026-22585 affects Salesforce Marketing Cloud Engagement versions prior to 2026-01-21.
What type of vulnerability is CVE-2026-22585?
CVE-2026-22585 is a use of a broken or risky cryptographic algorithm vulnerability.
What components of Salesforce Marketing Cloud Engagement are impacted by CVE-2026-22585?
CVE-2026-22585 impacts several components including CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage modules.