CVE-2026-22586
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-24

Last updated on: 2026-02-12

Assigner: Salesforce, Inc.

Description
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-24
Last Modified
2026-02-12
Generated
2026-06-16
AI Q&A
2026-01-24
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
salesforce marketing_cloud_engagement to 2026-01-21 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a Hard-coded Cryptographic Key issue in Salesforce Marketing Cloud Engagement, affecting modules such as CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, and View As Webpage. It allows Web Services Protocol Manipulation.

Impact Analysis

The vulnerability could allow attackers to manipulate web services protocols due to the hard-coded cryptographic key, potentially compromising the security of affected Salesforce Marketing Cloud Engagement modules.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart