Salesforce.com IncZenity disclosed three SalesBleed vulnerabilities in Salesforce Agentforce enabling zero-click CRM data exfiltration and phishing, which Salesforce had to patch.

Zenity Labs today disclosed SalesBleed, a set of three security vulnerabilities in Salesforce Agentforce that could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data and turn an enterprise agent into a vehicle for phishing attacks. Two of the three vulnerabilities enable zero-click data exfiltration, transmitting sensitive Salesforce data to attacker-controlled infrastructure without any employee click or approval, while the third lets attackers weaponize the trusted identity of an Agentforce-connected Slack agent to distribute phishing messages from inside the enterprise. The research found multiple weaknesses in Trusted URLs, the Salesforce mechanism meant to stop Agentforce from displaying URLs and images from untrusted sources, plus a separate flaw in the Agentforce-Slack integration. Zenity Labs disclosed the findings to Salesforce on June 1, 2026, and Salesforce addressed the specific Trusted URLs bypasses within approximately two weeks and also remediated the Slack attribution issue. Michael Bargury, co-founder and CTO of Zenity, said hard boundaries remain one of the strongest tools for containing AI agents, but they are still software, and when those controls fail, what remains is a privileged access agent with high autonomy and no bounds.
Salesforce.com IncZenity disclosed three SalesBleed vulnerabilities in Salesforce Agentforce enabling zero-click CRM data exfiltration and phishing, which Salesforce had to patch.
CTO Realty Growth IncZenity Labs' security research uncovered and disclosed the SalesBleed flaws in Salesforce Agentforce, showcasing its AI-agent security expertise.