RevOps and Data

Twice in a year, Salesforce could not stop its AI handing over customer records. Those records are people who filled in a form.

The people whose details came out of the CRM never chose Salesforce, never saw the patch notes, and will never be told.
September 28, 2026

Twice in twelve months, researchers have taken control of Salesforce's AI assistant by typing instructions into a form that anyone on the internet can fill in. Both times the assistant did what the stranger wrote. In the first case it pulled sales leads out of the CRM and sent them to a domain the researchers had bought for five dollars. Salesforce fixed that one in September 2025 and the last of the new batch on September 21, 112 days after it was reported. Nobody has reported either being used against a real company.

The patch notes are not the story. The story is that the same door has worked twice, and the people whose records came out of it never agreed to any of it. They filled in a form on some company's website because they wanted a price or a demo. That company bought Salesforce. Salesforce built an assistant. The assistant reads the box strangers type into, and Salesforce has now twice been unable to stop it acting on what it reads.

Same form, twelve months apart

In September 2025, Noma Security disclosed ForcedLeak, a prompt-injection chain rated 9.4, which hid its payload in the 42,000 character description field of a Web-to-Lead submission. That is the form sitting behind "contact us" on a large number of B2B websites. The researchers found an expired domain still on Salesforce's list of trusted addresses, bought it for five dollars, and collected the stolen lead data there. Salesforce's answer was to start enforcing that list, so agents could not send anything to an address that was not on it.

Read the sequence back slowly. The platform sells a company a form so strangers can write into its database. Then it sells the company an assistant that reads what the strangers wrote and believes it. Then it sells the company a list of approved addresses so the assistant cannot mail the results to whoever asked. Then somebody buys an address on the approved list for five dollars.

The second time, the fix was the thing that failed

SalesBleed, the name Zenity Labs gave this month's set of three flaws, is not a new category of problem. One got data out while the trusted-address check falsely reported that the content had been blocked. A second exploited the way that same check parsed certain top-level domains and character sequences. Both went around the control Salesforce shipped after ForcedLeak. Salesforce's answer this time was to push the trusted-address check deeper into core components, and to change the default so that Agentforce actions in Slack now ask a user to confirm before sending.

An allowlist assumes you can name the bad destinations in advance. The input here is written by anyone with a browser, and the instruction it carries is not code, it is a sentence.

The phishing arrives wearing the company's own badge

The third flaw is the one that should worry anyone who has ever filled in a security questionnaire. Zenity used the assistant's Slack integration to send messages through the assistant's own trusted identity, without naming the real sender. Employees got a request from a system already working inside their company rather than from a stranger. Specially built links made it worse, because Slack unfurls links automatically, so CRM data left the building as soon as the message appeared and nobody had to click anything.

We argued last week that the answer to a deepfaked colleague on a video call is to hang up and verify out of band. Same problem, different pipe. The impersonated party here is a system, and it has better standing inside the company than most of its vendors do.

Nobody can reconstruct what the assistants did

Zenity's own framing is that the risk pattern is not specific to Agentforce. An assistant is exposed when it takes untrusted input from outside, treats what it reads in a record as an instruction, renders links and images back to a person, and holds query access to sensitive data. That is close to the default build of a lead triage agent.

Whether anyone would even notice is a separate question. In LeanData's survey of 157 B2B practitioners, 93% had deployed at least one AI agent, roughly a third could not say how many were acting on their records, and 30% had found actions taken with no audit trail. We wrote earlier this month that AI now reads a CRM written from memory. It also writes to one, and three in ten teams cannot reconstruct what it did. If the company cannot reconstruct it, the person who filled in the form has no chance.

Which is the part worth sitting with. Every form on every website is a promise: type your details in here and we will look after them. That promise now runs through a vendor's ability to control an assistant nobody outside the company can see, and that vendor has been beaten at the same door twice. Salesforce will patch the third one too. Before it does, ask your own vendors a question their AI roadmap does not answer: which agents read records submitted by strangers, and what can those agents query. Any company that cannot answer that today will answer it later in a breach notification, and the notification will carry its name, not Salesforce's.

  1. The Register, "Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing," Jessica Lyons, September 24, 2026 theregister.com
  2. SecurityWeek, "'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration," Ionut Arghire, September 25, 2026 securityweek.com
  3. Infosecurity Magazine, "Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk," Kevin Poireault, September 25, 2026 infosecurity-magazine.com
  4. The Register, "Prompt injection and a $5 domain trick Salesforce Agentforce into leaking sales data," September 26, 2025, on ForcedLeak by Noma Security, CVSS 9.4 theregister.com
  5. Noma Security, ForcedLeak research noma.security
  6. MarTech, "GTM teams are losing track of their AI agents," Constantine von Hoffman, September 25, 2026, reporting LeanData's 2026 State of AI Go-to-Market Readiness Report, 157 B2B practitioners, fielded May 2026 martech.org
  7. Undivided Attention, "41% of CISOs met a deepfake on an employee call in the past year," September 23, 2026 mobilocard.com/news
  8. Undivided Attention, "Every revenue team in the study runs AI. The bottleneck they name is still typing into the CRM," September 8, 2026 mobilocard.com/news