Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesforce
Salesforce marketing Cloud Engagement |
|
| Vendors & Products |
Salesforce
Salesforce marketing Cloud Engagement |
Sat, 24 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026. | |
| Weaknesses | CWE-321 | |
| References |
|
Status: PUBLISHED
Assigner: Salesforce
Published: 2026-01-24T00:17:08.285Z
Updated: 2026-01-26T18:10:35.427Z
Reserved: 2026-01-07T19:03:25.721Z
Link: CVE-2026-22586
Updated: 2026-01-26T16:25:46.791Z
Status : Awaiting Analysis
Published: 2026-01-24T01:15:50.283
Modified: 2026-01-26T19:16:23.930
Link: CVE-2026-22586
No data.