Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
History

Sat, 24 Jan 2026 00:45:00 +0000

Type Values Removed Values Added
Description Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
Weaknesses CWE-321
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Salesforce

Published:

Updated: 2026-01-24T00:17:08.285Z

Reserved: 2026-01-07T19:03:25.721Z

Link: CVE-2026-22586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-24T01:15:50.283

Modified: 2026-01-24T01:15:50.283

Link: CVE-2026-22586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.