CVE-2026-22586: Critical severity Salesforce Marketing Cloud Engagement vulnerability
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22586?
CVE-2026-22586 is classified as a significant vulnerability due to its potential for exploitation through web services protocol manipulation.
How do I fix CVE-2026-22586?
To fix CVE-2026-22586, update your Salesforce Marketing Cloud Engagement software to the latest version released after January 21, 2026.
What components of Salesforce Marketing Cloud Engagement are affected by CVE-2026-22586?
CVE-2026-22586 affects multiple modules including CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage.
What are the potential impacts of exploiting CVE-2026-22586?
Exploitation of CVE-2026-22586 may allow unauthorized manipulation of web services, leading to data breaches or unauthorized access.
When was CVE-2026-22586 reported?
CVE-2026-22586 was reported prior to January 2, 2026.