CVE-2026-22585

CVE-2026-22585

Vendor Salesforce
Product Marketing Cloud Engagement
Weakness CWE-327 · Broken crypto
Published January 24, 2026
Last update April 29, 2026

CVSS base score

What the vulnerability does

01Description

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

Key dates

02Disclosure timeline

January 24, 2026 CVE published
April 29, 2026 Record updated