Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 24 Jan 2026 00:45:00 +0000

Type Values Removed Values Added
Description Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Weaknesses CWE-321
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Salesforce

Published:

Updated: 2026-01-24T00:17:08.285Z

Reserved: 2026-01-07T19:03:25.721Z

Link: CVE-2026-22586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-24T01:15:50.283

Modified: 2026-01-24T01:15:50.283

Link: CVE-2026-22586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses