Home

Description

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

PUBLISHED Reserved 2026-01-07 | Published 2026-01-24 | Updated 2026-01-27 | Assigner Salesforce

Problem types

CWE-321 Hard-coded Cryptographic Key

Product status

Default status
unaffected

Any version before January 21, 2026
affected

References

help.salesforce.com/s/articleView?id=005299346&type=1

cve.org (CVE-2026-22586)

nvd.nist.gov (CVE-2026-22586)

Download JSON