Salesforce Marketing Cloud Engagement Web Services Protocol Manipulation Vulnerability

Vulnerability

A vulnerability allowing Web Services Protocol Manipulation has been identified in Salesforce Marketing Cloud Engagement. This issue arises from the use of a broken or risky cryptographic algorithm and affects several modules, including CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage. The vulnerability was present in Marketing Cloud Engagement prior to January 21, 2026.

Impact

Exploitation of this vulnerability allowed for Web Services Protocol Manipulation, potentially leading to unauthorized actions or data exposure within the affected modules.

Remediation

Salesforce has deployed enhanced AES-GCM encryption across the Marketing Cloud Engagement platform. For customers, this deployment was completed on January 21, 2026, at 23:00 UTC. Links generated in emails sent after this date use the new encryption and are not vulnerable to these issues.

Added: Jan 24, 2026, 1:24 AM
Updated: Jan 24, 2026, 1:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
7.4
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.