[{"id":20000217,"subject":"Security Advisory: Unusual Activity in a Third Party Connected App","body":"We want to inform our customers about a recent security incident involving the Drift app, published by Salesloft, that was installed by individual customers. Salesforce security teams detected unusual activity that may have resulted in unauthorized access to a small number of customers’ orgs data via the app's connection to Salesforce.\n\nIt is important to note that this issue did not stem from a vulnerability within the core Salesforce platform, but rather from a compromise of the app's connection.\n\nUpon detecting the activity, Salesloft, in collaboration with Salesforce, invalidated active Access and Refresh Tokens, and removed Drift from AppExchange. We then notified affected customers.\n\nWe’re continuing to work with Salesloft as part of our investigation and provide updates as appropriate, including notifying and supporting affected customers with remediation. If you need support, please reach out through Salesforce Help: https://help.salesforce.com/s. ","incidentId":null,"publicView":true,"startDate":"2025-08-27T00:56:00.000Z","endDate":"2026-06-17T20:55:00.000Z","createdAt":"2025-08-26T17:59:10.716Z","updatedAt":"2026-06-17T20:54:25.818Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"Salesforce has re-enabled integrations with Salesloft technologies, with the exception of any Drift app. Drift will remain disabled until further notice as part of our continued response to the security incident. This decision follows security measures and remediation steps implemented by Salesloft, which were independently validated by Mandiant.\n\nFor full details and guidance from Salesforce, please continue to follow https://help.salesforce.com/s/articleView?id=005134951&type=1. \nFor Salesloft’s latest investigation and remediation updates, see https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations","createdAt":"2025-09-07T17:51:45.082Z","updatedAt":"2025-09-07T17:51:45.085Z","entryType":"informational_message_update","sourceId":20000326,"sourceType":"update"},{"title":"Update","content":"Salesforce has disabled all integrations between Salesforce and Salesloft technologies, including the Drift app. As a result, organizations will not be able to connect to Salesforce via any Salesloft apps until further notice. Our teams are continuing to assess the situation, and we will provide further updates as appropriate. \n\nFor additional details, including guidance and future updates, please visit our knowledge article: https://help.salesforce.com/s/articleView?id=005134951&type=1.","createdAt":"2025-08-28T19:16:16.810Z","updatedAt":"2025-08-28T19:16:16.814Z","entryType":"informational_message_update","sourceId":20000325,"sourceType":"update"},{"title":"Update","content":"To protect our customers, Salesforce has disabled the connection between the Drift app, published by Salesloft, and Salesforce as part of our response to the recent security incident. This issue is limited to the Drift app’s connection and did not arise from a vulnerability within the Salesforce platform.\n\nOn August 28, 2025, at 04:09 UTC, we took this action out of an abundance of caution and as part of our ongoing security investigation. As a result, customers will not be able to connect to Salesforce via the Drift app until further notice.\n\nDisabling the connection is a precautionary measure to help safeguard customer environments while we continue to assess and address the situation. We recognize this change may cause disruption and will provide further updates as more information becomes available.\n\nFor additional details, please visit: https://help.salesforce.com/s/articleView?id=005134951&type=1","createdAt":"2025-08-28T04:39:04.062Z","updatedAt":"2025-08-28T04:39:04.067Z","entryType":"informational_message_update","sourceId":20000324,"sourceType":"update"},{"title":"Security Advisory: Unusual Activity in a Third Party Connected App","content":"We want to inform our customers about a recent security incident involving the Drift app, published by Salesloft, that was installed by individual customers. Salesforce security teams detected unusual activity that may have resulted in unauthorized access to a small number of customers’ orgs data via the app's connection to Salesforce.\n\nIt is important to note that this issue did not stem from a vulnerability within the core Salesforce platform, but rather from a compromise of the app's connection.\n\nUpon detecting the activity, Salesloft, in collaboration with Salesforce, invalidated active Access and Refresh Tokens, and removed Drift from AppExchange. We then notified affected customers.\n\nWe’re continuing to work with Salesloft as part of our investigation and provide updates as appropriate, including notifying and supporting affected customers with remediation. If you need support, please reach out through Salesforce Help: https://help.salesforce.com/s. ","createdAt":"2025-08-26T17:59:10.716Z","updatedAt":"2026-06-17T20:54:25.818Z","entryType":"informational_message_created","sourceId":20000217,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000324,"message":"To protect our customers, Salesforce has disabled the connection between the Drift app, published by Salesloft, and Salesforce as part of our response to the recent security incident. This issue is limited to the Drift app’s connection and did not arise from a vulnerability within the Salesforce platform.\n\nOn August 28, 2025, at 04:09 UTC, we took this action out of an abundance of caution and as part of our ongoing security investigation. As a result, customers will not be able to connect to Salesforce via the Drift app until further notice.\n\nDisabling the connection is a precautionary measure to help safeguard customer environments while we continue to assess and address the situation. We recognize this change may cause disruption and will provide further updates as more information becomes available.\n\nFor additional details, please visit: https://help.salesforce.com/s/articleView?id=005134951&type=1","createdAt":"2025-08-28T04:39:04.062Z","updatedAt":"2025-08-28T04:39:04.067Z","GeneralMessageId":20000217},{"id":20000325,"message":"Salesforce has disabled all integrations between Salesforce and Salesloft technologies, including the Drift app. As a result, organizations will not be able to connect to Salesforce via any Salesloft apps until further notice. Our teams are continuing to assess the situation, and we will provide further updates as appropriate. \n\nFor additional details, including guidance and future updates, please visit our knowledge article: https://help.salesforce.com/s/articleView?id=005134951&type=1.","createdAt":"2025-08-28T19:16:16.810Z","updatedAt":"2025-08-28T19:16:16.814Z","GeneralMessageId":20000217},{"id":20000326,"message":"Salesforce has re-enabled integrations with Salesloft technologies, with the exception of any Drift app. Drift will remain disabled until further notice as part of our continued response to the security incident. This decision follows security measures and remediation steps implemented by Salesloft, which were independently validated by Mandiant.\n\nFor full details and guidance from Salesforce, please continue to follow https://help.salesforce.com/s/articleView?id=005134951&type=1. \nFor Salesloft’s latest investigation and remediation updates, see https://trust.salesloft.com/?uid=Update+on+Mandiant+Drift+and+Salesloft+Application+Investigations","createdAt":"2025-09-07T17:51:45.082Z","updatedAt":"2025-09-07T17:51:45.085Z","GeneralMessageId":20000217}]},{"id":20000244,"subject":"Security Advisory: Protecting Experience Cloud Sites from Guest User Misconfigurations ","body":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity. These attempts are focused on customer configuration settings that, if not properly secured, may increase exposure.\n\nWe encourage customers to review their Experience Cloud guest user settings and take immediate recommended actions. For additional details and steps to help protect your org, please see our blog: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/","incidentId":null,"publicView":true,"startDate":"2026-03-08T04:00:00.000Z","endDate":null,"createdAt":"2026-03-07T23:06:36.591Z","updatedAt":"2026-03-07T23:07:25.213Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Update","content":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nWe have identified additional guidance for customers to help protect their orgs. Please see our updated blog for recommended actions: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity.","createdAt":"2026-03-12T20:20:56.359Z","updatedAt":"2026-03-12T20:20:56.361Z","entryType":"informational_message_update","sourceId":20000406,"sourceType":"update"},{"title":"Security Advisory: Protecting Experience Cloud Sites from Guest User Misconfigurations ","content":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity. These attempts are focused on customer configuration settings that, if not properly secured, may increase exposure.\n\nWe encourage customers to review their Experience Cloud guest user settings and take immediate recommended actions. For additional details and steps to help protect your org, please see our blog: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/","createdAt":"2026-03-07T23:06:36.591Z","updatedAt":"2026-03-07T23:07:25.213Z","entryType":"informational_message_created","sourceId":20000244,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000406,"message":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nWe have identified additional guidance for customers to help protect their orgs. Please see our updated blog for recommended actions: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity.","createdAt":"2026-03-12T20:20:56.359Z","updatedAt":"2026-03-12T20:20:56.361Z","GeneralMessageId":20000244}]},{"id":20000256,"subject":"Disruption to Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations","body":"Issue: We’re aware of an issue impacting Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations starting on June 12th at 13:20 UTC.\n\nImpact: Customers may experience disruptions with Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations that rely on a third-party vendor's product catalog. ","incidentId":"91593682","publicView":true,"startDate":"2026-06-12T17:20:00.000Z","endDate":"2026-06-12T18:00:00.000Z","createdAt":"2026-06-12T15:39:28.396Z","updatedAt":"2026-06-12T18:42:52.273Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"We have verified that all affected services have recovered and are operating normally. This incident was resolved as of June 12, 2026, at 18:00 UTC.","createdAt":"2026-06-12T18:42:52.276Z","updatedAt":"2026-06-12T18:42:52.278Z","entryType":"informational_message_update","sourceId":20000444,"sourceType":"update"},{"title":"Update","content":"We are seeing some improvement in the successful execution of business service APIs. The following services are now out of impact: Advertising Studio, Data360, Service Cloud Messaging  Facebook channels), and Marketing Cloud Engagement (WA channel).\n\nService Cloud Unified Messaging WhatsApp (UCP WhatsApp) is also seeing improvements. We are continuing to actively monitor that service.\n\nWe'll provide further updates as more information becomes available.","createdAt":"2026-06-12T18:09:20.693Z","updatedAt":"2026-06-12T18:09:20.694Z","entryType":"informational_message_update","sourceId":20000443,"sourceType":"update"},{"title":"Update","content":"The trigger has been identified as a partner outage affecting all business service APIs. We are actively engaged with the third-party vendor to expedite remediation and recovery.\n\nFull customer impact is still being assessed. As this is a significant incident, any business service integration dependent on the third-party service provider is likely to be impacted.\n\nWe'll provide further updates as more information becomes available.","createdAt":"2026-06-12T17:37:05.367Z","updatedAt":"2026-06-12T18:09:09.669Z","entryType":"informational_message_update","sourceId":20000442,"sourceType":"update"},{"title":"Disruption to Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations","content":"Issue: We’re aware of an issue impacting Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations starting on June 12th at 13:20 UTC.\n\nImpact: Customers may experience disruptions with Advertising Studio, Data360, Service Cloud Messaging (WA and Facebook channels), and Marketing Cloud Engagement (WA channel) integrations that rely on a third-party vendor's product catalog. ","createdAt":"2026-06-12T15:39:28.396Z","updatedAt":"2026-06-12T18:42:52.273Z","entryType":"informational_message_created","sourceId":20000256,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000442,"message":"The trigger has been identified as a partner outage affecting all business service APIs. We are actively engaged with the third-party vendor to expedite remediation and recovery.\n\nFull customer impact is still being assessed. As this is a significant incident, any business service integration dependent on the third-party service provider is likely to be impacted.\n\nWe'll provide further updates as more information becomes available.","createdAt":"2026-06-12T17:37:05.367Z","updatedAt":"2026-06-12T18:09:09.669Z","GeneralMessageId":20000256},{"id":20000443,"message":"We are seeing some improvement in the successful execution of business service APIs. The following services are now out of impact: Advertising Studio, Data360, Service Cloud Messaging  Facebook channels), and Marketing Cloud Engagement (WA channel).\n\nService Cloud Unified Messaging WhatsApp (UCP WhatsApp) is also seeing improvements. We are continuing to actively monitor that service.\n\nWe'll provide further updates as more information becomes available.","createdAt":"2026-06-12T18:09:20.693Z","updatedAt":"2026-06-12T18:09:20.694Z","GeneralMessageId":20000256},{"id":20000444,"message":"We have verified that all affected services have recovered and are operating normally. This incident was resolved as of June 12, 2026, at 18:00 UTC.","createdAt":"2026-06-12T18:42:52.276Z","updatedAt":"2026-06-12T18:42:52.278Z","GeneralMessageId":20000256}]},{"id":20000224,"subject":"Security Advisory: Ongoing Response to Social Engineering Threats","body":"We are aware of recent extortion attempts by threat actors, which we have investigated in partnership with external experts and authorities. Our findings indicate these attempts relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support. At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.\nOur security teams are actively working to protect customer environments and data, providing guidance and support. Customers identified as potentially affected have been notified directly. If you have not received a notification, we currently have no evidence suggesting any impact to your account. We continue to monitor the situation closely and encourage customers to remain vigilant against phishing and social engineering attempts, which remain common tactics used by threat actors.\n\nFor guidance, please review our blog post (https://www.salesforce.com/blog/protect-against-social-engineering), knowledge article (https://help.salesforce.com/s/articleView?id=005226734&type=1), and reach out through the Salesforce Help portal if you need support.","incidentId":null,"publicView":true,"startDate":"2025-10-02T14:50:00.000Z","endDate":null,"createdAt":"2025-10-02T15:58:29.023Z","updatedAt":"2025-10-17T11:49:26.040Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Update","content":"Salesforce is monitoring social engineering campaigns targeting third-party identity providers (IdPs) across the industry. In these attacks, threat actors use fraudulent login pages or impersonate IT support through voice calls to steal credentials or MFA codes, or to trick users into authorizing malicious connected apps. If an IdP account is compromised, attackers may attempt to access connected applications.\n\nPlease note this issue does not stem from a vulnerability inherent to Salesforce; these attacks rely on social engineering and deceptive authentication prompts.\n\nOur security teams are actively working to protect customers and have notified potentially affected accounts. For guidance and mitigations, please review our blog post (https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/) and knowledge article (https://help.salesforce.com/s/articleView?language=en_US&id=005226734&type=1). For support, contact Salesforce Customer Support via https://help.salesforce.com/s/?language=en_US.","createdAt":"2026-01-30T15:58:12.170Z","updatedAt":"2026-01-30T15:58:12.172Z","entryType":"informational_message_update","sourceId":20000402,"sourceType":"update"},{"title":"Security Advisory: Ongoing Response to Social Engineering Threats","content":"We are aware of recent extortion attempts by threat actors, which we have investigated in partnership with external experts and authorities. Our findings indicate these attempts relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support. At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.\nOur security teams are actively working to protect customer environments and data, providing guidance and support. Customers identified as potentially affected have been notified directly. If you have not received a notification, we currently have no evidence suggesting any impact to your account. We continue to monitor the situation closely and encourage customers to remain vigilant against phishing and social engineering attempts, which remain common tactics used by threat actors.\n\nFor guidance, please review our blog post (https://www.salesforce.com/blog/protect-against-social-engineering), knowledge article (https://help.salesforce.com/s/articleView?id=005226734&type=1), and reach out through the Salesforce Help portal if you need support.","createdAt":"2025-10-02T15:58:29.023Z","updatedAt":"2025-10-17T11:49:26.040Z","entryType":"informational_message_created","sourceId":20000224,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000402,"message":"Salesforce is monitoring social engineering campaigns targeting third-party identity providers (IdPs) across the industry. In these attacks, threat actors use fraudulent login pages or impersonate IT support through voice calls to steal credentials or MFA codes, or to trick users into authorizing malicious connected apps. If an IdP account is compromised, attackers may attempt to access connected applications.\n\nPlease note this issue does not stem from a vulnerability inherent to Salesforce; these attacks rely on social engineering and deceptive authentication prompts.\n\nOur security teams are actively working to protect customers and have notified potentially affected accounts. For guidance and mitigations, please review our blog post (https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/) and knowledge article (https://help.salesforce.com/s/articleView?language=en_US&id=005226734&type=1). For support, contact Salesforce Customer Support via https://help.salesforce.com/s/?language=en_US.","createdAt":"2026-01-30T15:58:12.170Z","updatedAt":"2026-01-30T15:58:12.172Z","GeneralMessageId":20000224}]},{"id":20000259,"subject":"Marketing Cloud MCP Connectivity Issues","body":"Issue: We’re aware of an issue which started at approximately 13:20 UTC that is impacting Marketing Cloud MCP services. \n\nImpact: Customers attempting to utilize the service will observe connection failures. ","incidentId":null,"publicView":true,"startDate":"2026-07-24T13:20:00.000Z","endDate":"2026-07-24T19:28:00.000Z","createdAt":"2026-07-24T17:47:07.220Z","updatedAt":"2026-07-24T19:51:07.044Z","externalId":"93287151","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"productSpecific","status":"Resolved","timeline":[{"title":"Update","content":"At 19:28 UTC, we have resolved this issue affecting access to the Marketing Cloud Engagement MCP service. We identified that the issue was triggered by the decommission of a related service, which removed a shared outbound access. We resolved the issue by redeploying the outbound access configuration to all affected instances.\n\nWe apologize for how you and your business may have been affected by this incident. We will thoroughly investigate the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-24T19:51:07.041Z","updatedAt":"2026-07-24T19:51:07.042Z","entryType":"informational_message_update","sourceId":20000447,"sourceType":"update"},{"title":"Update","content":"We continue to work towards mitigation. At this time we don’t have any additional updates to share.\n\nWe'll provide an update in 60 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T19:17:39.841Z","updatedAt":"2026-07-24T19:17:39.844Z","entryType":"informational_message_update","sourceId":20000446,"sourceType":"update"},{"title":"Update","content":"We’ve identified that a policy configuration change blocked traffic to service hosts. To mitigate this issue, we’re preparing to redeploy the last known-good policy to reestablish connections.\n\nWe'll provide an update in 30 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T18:39:10.350Z","updatedAt":"2026-07-24T18:39:10.352Z","entryType":"informational_message_update","sourceId":20000445,"sourceType":"update"},{"title":"Marketing Cloud MCP Connectivity Issues","content":"Issue: We’re aware of an issue which started at approximately 13:20 UTC that is impacting Marketing Cloud MCP services. \n\nImpact: Customers attempting to utilize the service will observe connection failures. ","createdAt":"2026-07-24T17:47:07.220Z","updatedAt":"2026-07-24T19:51:07.044Z","entryType":"informational_message_created","sourceId":20000259,"sourceType":"message"}],"productKeys":["Marketing_Cloud"],"InformationalMessageUpdates":[{"id":20000445,"message":"We’ve identified that a policy configuration change blocked traffic to service hosts. To mitigate this issue, we’re preparing to redeploy the last known-good policy to reestablish connections.\n\nWe'll provide an update in 30 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T18:39:10.350Z","updatedAt":"2026-07-24T18:39:10.352Z","GeneralMessageId":20000259},{"id":20000446,"message":"We continue to work towards mitigation. At this time we don’t have any additional updates to share.\n\nWe'll provide an update in 60 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T19:17:39.841Z","updatedAt":"2026-07-24T19:17:39.844Z","GeneralMessageId":20000259},{"id":20000447,"message":"At 19:28 UTC, we have resolved this issue affecting access to the Marketing Cloud Engagement MCP service. We identified that the issue was triggered by the decommission of a related service, which removed a shared outbound access. We resolved the issue by redeploying the outbound access configuration to all affected instances.\n\nWe apologize for how you and your business may have been affected by this incident. We will thoroughly investigate the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-24T19:51:07.041Z","updatedAt":"2026-07-24T19:51:07.042Z","GeneralMessageId":20000259}]},{"id":20000260,"subject":"Hyperlink Rendering Issue on Agentforce Web Agents with Next Gen Authoring","body":"Issue: We're aware of an issue affecting customers using Agentforce Web Agents with Next Gen Authoring (NGA).\n\nImpact: Users are unable to navigate to hyperlinks provided in agent responses. The link text displays correctly, but the links are not clickable.","incidentId":null,"publicView":true,"startDate":"2026-07-30T04:00:00.000Z","endDate":"2026-07-30T22:44:00.000Z","createdAt":"2026-07-30T20:06:00.393Z","updatedAt":"2026-07-30T22:48:28.494Z","externalId":"93510980","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"As of 22:44 the issue affecting customers using Agentforce Web Agents with Next Gen Authoring (NGA) has been resolved.\n\nWe apologize for how you and your business may have been affected by this. We will perform a full investigation of the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-30T22:48:28.489Z","updatedAt":"2026-07-30T22:48:28.492Z","entryType":"informational_message_update","sourceId":20000450,"sourceType":"update"},{"title":"Update","content":"We have confirmed in a test environment that reverting a recent change resolves the issue, and are now preparing to roll back this change across all impacted environments.\n\nWe'll provide another update as additional information becomes available.","createdAt":"2026-07-30T22:14:38.969Z","updatedAt":"2026-07-30T22:14:38.972Z","entryType":"informational_message_update","sourceId":20000449,"sourceType":"update"},{"title":"Update","content":"We’ve identified the trigger for this issue and have turned Web Agents off while we work to develop a fix to mitigate impact as quickly as possible. . \n\nWe'll provide another update as additional information becomes available.","createdAt":"2026-07-30T20:36:01.202Z","updatedAt":"2026-07-30T20:36:01.204Z","entryType":"informational_message_update","sourceId":20000448,"sourceType":"update"},{"title":"Hyperlink Rendering Issue on Agentforce Web Agents with Next Gen Authoring","content":"Issue: We're aware of an issue affecting customers using Agentforce Web Agents with Next Gen Authoring (NGA).\n\nImpact: Users are unable to navigate to hyperlinks provided in agent responses. The link text displays correctly, but the links are not clickable.","createdAt":"2026-07-30T20:06:00.393Z","updatedAt":"2026-07-30T22:48:28.494Z","entryType":"informational_message_created","sourceId":20000260,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000448,"message":"We’ve identified the trigger for this issue and have turned Web Agents off while we work to develop a fix to mitigate impact as quickly as possible. . \n\nWe'll provide another update as additional information becomes available.","createdAt":"2026-07-30T20:36:01.202Z","updatedAt":"2026-07-30T20:36:01.204Z","GeneralMessageId":20000260},{"id":20000449,"message":"We have confirmed in a test environment that reverting a recent change resolves the issue, and are now preparing to roll back this change across all impacted environments.\n\nWe'll provide another update as additional information becomes available.","createdAt":"2026-07-30T22:14:38.969Z","updatedAt":"2026-07-30T22:14:38.972Z","GeneralMessageId":20000260},{"id":20000450,"message":"As of 22:44 the issue affecting customers using Agentforce Web Agents with Next Gen Authoring (NGA) has been resolved.\n\nWe apologize for how you and your business may have been affected by this. We will perform a full investigation of the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-30T22:48:28.489Z","updatedAt":"2026-07-30T22:48:28.492Z","GeneralMessageId":20000260}]},{"id":20000255,"subject":"Failed Conversation History Retrieval on Agentforce","body":"Issue: We're investigating an issue that may prevent some customers from being able to read conversation histories. We've identified a recent code change, which was deployed globally that triggered the system to incorrectly evaluate an end time of zero (or a blank value) in GET calls, resulting in failed retrieval requests.\n\nImpact: During this time, affected customers may be unable to read their conversation histories.\n","incidentId":null,"publicView":true,"startDate":"2026-06-04T19:02:00.000Z","endDate":"2026-06-04T22:35:00.000Z","createdAt":"2026-06-04T19:05:10.354Z","updatedAt":"2026-06-04T22:54:02.744Z","externalId":"91360025","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"We’ve successfully deployed the fix to all remaining instances and, following a period of close monitoring, have confirmed that services were fully restored as of 22:35 UTC. Customers should no longer experience any issues when viewing their conversation histories. \n\nWe’ll perform a full investigation of the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future. We apologize for how you and your business may have been affected by this incident.","createdAt":"2026-06-04T22:54:02.748Z","updatedAt":"2026-06-04T22:54:02.750Z","entryType":"informational_message_update","sourceId":20000441,"sourceType":"update"},{"title":"Update","content":"We’re actively working on the fix-forward, and while the build itself is progressing steadily through our pipeline, it's taking slightly longer than initially anticipated.\n\nWe’re monitoring the recovery closely and will provide an update upon completion of the fix, or sooner if significant information becomes available.","createdAt":"2026-06-04T22:08:22.870Z","updatedAt":"2026-06-04T22:08:22.882Z","entryType":"informational_message_update","sourceId":20000440,"sourceType":"update"},{"title":"Update","content":"We've rolled back the recent change that triggered this issue. Initial results are positive, and service has been restored for the majority of affected customers. We’re actively working on a targeted fix-forward for the remaining impacted instances, with an estimated completion time of two hours.\n\nWe’re monitoring the recovery closely and will provide an update upon completion of the fix, or sooner if significant information becomes available.","createdAt":"2026-06-04T20:00:31.231Z","updatedAt":"2026-06-04T20:00:31.234Z","entryType":"informational_message_update","sourceId":20000439,"sourceType":"update"},{"title":"Failed Conversation History Retrieval on Agentforce","content":"Issue: We're investigating an issue that may prevent some customers from being able to read conversation histories. We've identified a recent code change, which was deployed globally that triggered the system to incorrectly evaluate an end time of zero (or a blank value) in GET calls, resulting in failed retrieval requests.\n\nImpact: During this time, affected customers may be unable to read their conversation histories.\n","createdAt":"2026-06-04T19:05:10.354Z","updatedAt":"2026-06-04T22:54:02.744Z","entryType":"informational_message_created","sourceId":20000255,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000439,"message":"We've rolled back the recent change that triggered this issue. Initial results are positive, and service has been restored for the majority of affected customers. We’re actively working on a targeted fix-forward for the remaining impacted instances, with an estimated completion time of two hours.\n\nWe’re monitoring the recovery closely and will provide an update upon completion of the fix, or sooner if significant information becomes available.","createdAt":"2026-06-04T20:00:31.231Z","updatedAt":"2026-06-04T20:00:31.234Z","GeneralMessageId":20000255},{"id":20000440,"message":"We’re actively working on the fix-forward, and while the build itself is progressing steadily through our pipeline, it's taking slightly longer than initially anticipated.\n\nWe’re monitoring the recovery closely and will provide an update upon completion of the fix, or sooner if significant information becomes available.","createdAt":"2026-06-04T22:08:22.870Z","updatedAt":"2026-06-04T22:08:22.882Z","GeneralMessageId":20000255},{"id":20000441,"message":"We’ve successfully deployed the fix to all remaining instances and, following a period of close monitoring, have confirmed that services were fully restored as of 22:35 UTC. Customers should no longer experience any issues when viewing their conversation histories. \n\nWe’ll perform a full investigation of the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future. We apologize for how you and your business may have been affected by this incident.","createdAt":"2026-06-04T22:54:02.748Z","updatedAt":"2026-06-04T22:54:02.750Z","GeneralMessageId":20000255}]},{"id":20000261,"subject":"Feature Degradation impacting alerting dashboards","body":"Issue: We’re aware of an issue impacting Proactive Monitoring dashboards for Salesforce customers, beginning at 13:35 UTC on August 10, 2026. \n\nImpact: A subset customers may not receive Proactive Monitoring alert notifications, and dashboards on the Proactive Monitoring Health portal may not display trend data.\n\nAdditional Information: There is no impact to Salesforce services for the affected customers.","incidentId":null,"publicView":true,"startDate":"2026-08-10T13:35:00.000Z","endDate":"2026-08-15T16:32:00.000Z","createdAt":"2026-08-15T15:40:42.090Z","updatedAt":"2026-08-15T16:56:00.072Z","externalId":"94141442","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"Issue: We identified an issue impacting Proactive Monitoring dashboards for Salesforce customers, beginning at 13:35 UTC on August 10, 2026.\n\nSome customers might not have received Proactive Monitoring alert notifications.\n\nResolution: The issue has been resolved and normal functionality has been restored.\n\nAdditional Information: There was no impact to Salesforce services for the affected customers.","createdAt":"2026-08-15T16:56:00.065Z","updatedAt":"2026-08-15T16:56:00.069Z","entryType":"informational_message_update","sourceId":20000451,"sourceType":"update"},{"title":"Feature Degradation impacting alerting dashboards","content":"Issue: We’re aware of an issue impacting Proactive Monitoring dashboards for Salesforce customers, beginning at 13:35 UTC on August 10, 2026. \n\nImpact: A subset customers may not receive Proactive Monitoring alert notifications, and dashboards on the Proactive Monitoring Health portal may not display trend data.\n\nAdditional Information: There is no impact to Salesforce services for the affected customers.","createdAt":"2026-08-15T15:40:42.090Z","updatedAt":"2026-08-15T16:56:00.072Z","entryType":"informational_message_created","sourceId":20000261,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000451,"message":"Issue: We identified an issue impacting Proactive Monitoring dashboards for Salesforce customers, beginning at 13:35 UTC on August 10, 2026.\n\nSome customers might not have received Proactive Monitoring alert notifications.\n\nResolution: The issue has been resolved and normal functionality has been restored.\n\nAdditional Information: There was no impact to Salesforce services for the affected customers.","createdAt":"2026-08-15T16:56:00.065Z","updatedAt":"2026-08-15T16:56:00.069Z","GeneralMessageId":20000261}]},{"id":20000262,"subject":"Manage Connected Apps Feature Disruption","body":"Issue: On August 24, 2026, we became aware of a subset of customers who are experiencing timeout errors when trying to load the \"Manage Connected Apps\" page. This was caused by an authentication call introduced in version 264 and later backported to version 262.\n\nImpact: Some customers are unable to load the \"Manage Connected Apps\" page.\n\nNext Update: We will provide updated information and more details as soon as they become available.\n","incidentId":null,"publicView":true,"startDate":"2026-08-18T22:00:00.000Z","endDate":"2026-08-24T18:52:00.000Z","createdAt":"2026-08-24T17:11:09.572Z","updatedAt":"2026-08-24T18:54:19.763Z","externalId":"94489014","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Update","content":"We've resolved this issue by implementing a fix that disabled the impacted functionality. This restored the \"Manage Connected Apps\" page to normal operation. We apologize for how this incident may have affected your business. We will thoroughly investigate this incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-08-24T18:54:19.758Z","updatedAt":"2026-08-24T18:54:19.760Z","entryType":"informational_message_update","sourceId":20000453,"sourceType":"update"},{"title":"Update","content":"Update 1: \nUpon further investigation, we've determined that the start time of impact is different than initially understood. We've revised the start time of this Trust post to August 18, 2026 at 22:00 UTC, to more accurately reflect the time customers may have begun to experience impact. We apologize for any confusion caused by this.\n\nWe identified the technical trigger and we're preparing to implement a fix to resolve the impact. Thank you for your patience while we work to implement a permanent fix for this issue. We'll provide an update in 2 hours or sooner if additional information becomes available.","createdAt":"2026-08-24T17:52:37.831Z","updatedAt":"2026-08-24T17:52:37.834Z","entryType":"informational_message_update","sourceId":20000452,"sourceType":"update"},{"title":"Manage Connected Apps Feature Disruption","content":"Issue: On August 24, 2026, we became aware of a subset of customers who are experiencing timeout errors when trying to load the \"Manage Connected Apps\" page. This was caused by an authentication call introduced in version 264 and later backported to version 262.\n\nImpact: Some customers are unable to load the \"Manage Connected Apps\" page.\n\nNext Update: We will provide updated information and more details as soon as they become available.\n","createdAt":"2026-08-24T17:11:09.572Z","updatedAt":"2026-08-24T18:54:19.763Z","entryType":"informational_message_created","sourceId":20000262,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000452,"message":"Update 1: \nUpon further investigation, we've determined that the start time of impact is different than initially understood. We've revised the start time of this Trust post to August 18, 2026 at 22:00 UTC, to more accurately reflect the time customers may have begun to experience impact. We apologize for any confusion caused by this.\n\nWe identified the technical trigger and we're preparing to implement a fix to resolve the impact. Thank you for your patience while we work to implement a permanent fix for this issue. We'll provide an update in 2 hours or sooner if additional information becomes available.","createdAt":"2026-08-24T17:52:37.831Z","updatedAt":"2026-08-24T17:52:37.834Z","GeneralMessageId":20000262},{"id":20000453,"message":"We've resolved this issue by implementing a fix that disabled the impacted functionality. This restored the \"Manage Connected Apps\" page to normal operation. We apologize for how this incident may have affected your business. We will thoroughly investigate this incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-08-24T18:54:19.758Z","updatedAt":"2026-08-24T18:54:19.760Z","GeneralMessageId":20000262}]},{"id":10001498,"subject":"U.S., EU, and UK Regulations on Software Provision to Russia","body":"Salesforce takes its sanctions and export control obligations seriously, and we require our customers and partners to do the same. Under current United States, European Union, and United Kingdom sanctions, the provision of enterprise management software to individuals or entities in Russia is prohibited. \n\nUntil further notice, we expect our customers and partners will not provide access to Salesforce products and services to their users or affiliates in Russia without appropriate legal authorization. Salesforce may implement technical access controls to support compliance with applicable laws, including as per compliance with OFAC’s Determination Pursuant to Section 1(a)(ii) of Executive Order 14071, European Union Council Regulation 2023/2878, and the United Kingdom Russia (Sanctions) (EU Exit) (Amendment) Regulations 2025.\n\nIf your organization requires access to Salesforce products or services in Russia, please contact your Salesforce account team to discuss our exceptions process.\n","incidentId":null,"publicView":true,"startDate":"2025-04-22T17:12:00.000Z","endDate":"2026-08-13T17:00:00.000Z","createdAt":"2025-04-22T17:13:23.193Z","updatedAt":"2026-08-13T17:12:04.093Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"U.S., EU, and UK Regulations on Software Provision to Russia","content":"Salesforce takes its sanctions and export control obligations seriously, and we require our customers and partners to do the same. Under current United States, European Union, and United Kingdom sanctions, the provision of enterprise management software to individuals or entities in Russia is prohibited. \n\nUntil further notice, we expect our customers and partners will not provide access to Salesforce products and services to their users or affiliates in Russia without appropriate legal authorization. Salesforce may implement technical access controls to support compliance with applicable laws, including as per compliance with OFAC’s Determination Pursuant to Section 1(a)(ii) of Executive Order 14071, European Union Council Regulation 2023/2878, and the United Kingdom Russia (Sanctions) (EU Exit) (Amendment) Regulations 2025.\n\nIf your organization requires access to Salesforce products or services in Russia, please contact your Salesforce account team to discuss our exceptions process.\n","createdAt":"2025-04-22T17:13:23.193Z","updatedAt":"2026-08-13T17:12:04.093Z","entryType":"informational_message_created","sourceId":10001498,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000258,"subject":"Salesforce Help Maintenance","body":"The scheduled maintenance for Salesforce Help that took place on June 19 from 4:45 PM PT to 7:15 PM PT has been completed successfully.\n\nFull functionality has been restored. Users can now log into Help Portal. Agentforce on Help is available, and users can view, create, and update support cases as normal. Any replies to case comment emails received during the maintenance window have been processed.\n\nAdditionally, Proactive Monitoring (ProM) has resumed. Signature customers can expect ProM alerts and notifications to be delivered as normal.\n\nThank you for your patience during the maintenance window. If you are still experiencing any issues, please contact Salesforce Support at 1-800-NO-SOFTWARE or visit sfdc.co/VbDcq to find your local number.","incidentId":null,"publicView":true,"startDate":"2026-06-19T03:07:00.000Z","endDate":"2026-06-20T02:15:00.000Z","createdAt":"2026-06-18T20:22:03.261Z","updatedAt":"2026-06-20T02:29:30.556Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Salesforce Help Maintenance","content":"The scheduled maintenance for Salesforce Help that took place on June 19 from 4:45 PM PT to 7:15 PM PT has been completed successfully.\n\nFull functionality has been restored. Users can now log into Help Portal. Agentforce on Help is available, and users can view, create, and update support cases as normal. Any replies to case comment emails received during the maintenance window have been processed.\n\nAdditionally, Proactive Monitoring (ProM) has resumed. Signature customers can expect ProM alerts and notifications to be delivered as normal.\n\nThank you for your patience during the maintenance window. If you are still experiencing any issues, please contact Salesforce Support at 1-800-NO-SOFTWARE or visit sfdc.co/VbDcq to find your local number.","createdAt":"2026-06-18T20:22:03.261Z","updatedAt":"2026-06-20T02:29:30.556Z","entryType":"informational_message_created","sourceId":20000258,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000246,"subject":"How Salesforce is preparing for the frontier AI threat landscape","body":"Anthropic’s announcement of Claude Mythos underscores a reality Salesforce has been preparing for: increasingly capable frontier AI models will continue to accelerate the evolution of the cybersecurity landscape.\n\nOur security teams are continuously evaluating how frontier models like Mythos may change attacker and defender capabilities, and we are applying those insights to strengthen our security posture and guide continued enhancements across our environment.\n\nWe view this as an acceleration of work already underway, not a departure from it. Salesforce has long invested in automation and AI to help identify risk, strengthen defenses, and support the trust our customers place in us.\n\nTrust remains our #1 value, and we remain focused on helping protect our customers’ data in a rapidly evolving threat environment.","incidentId":null,"publicView":true,"startDate":"2026-04-14T06:23:00.000Z","endDate":null,"createdAt":"2026-04-13T23:24:55.319Z","updatedAt":"2026-04-13T23:24:55.322Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"How Salesforce is preparing for the frontier AI threat landscape","content":"Anthropic’s announcement of Claude Mythos underscores a reality Salesforce has been preparing for: increasingly capable frontier AI models will continue to accelerate the evolution of the cybersecurity landscape.\n\nOur security teams are continuously evaluating how frontier models like Mythos may change attacker and defender capabilities, and we are applying those insights to strengthen our security posture and guide continued enhancements across our environment.\n\nWe view this as an acceleration of work already underway, not a departure from it. Salesforce has long invested in automation and AI to help identify risk, strengthen defenses, and support the trust our customers place in us.\n\nTrust remains our #1 value, and we remain focused on helping protect our customers’ data in a rapidly evolving threat environment.","createdAt":"2026-04-13T23:24:55.319Z","updatedAt":"2026-04-13T23:24:55.322Z","entryType":"informational_message_created","sourceId":20000246,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000227,"subject":"Security Alert: Phishing Campaign with Malicious links","body":"Salesforce is aware of and closely monitoring a phishing campaign appearing as fraudulent emails from Salesforce with a malicious link to download Remote Monitoring & Management (RMM) software.\n\nOur security teams are working diligently to contain this issue and urge all customers to maintain a high level of vigilance against phishing and social engineering attempts, as these remain frequently used tactics by threat actors. If you receive requests from Salesforce to install RMM software, we recommend you validate its legitimacy with Salesforce Support or architect teams prior to taking action by opening up a ticket through the Salesforce Help portal.\n\nFor guidance and support, please reach out through the Salesforce Help portal. You can also refer to this article for guidance on how to protect your environments from social engineering threats: https://www.salesforce.com/blog/protect-against-social-engineering/. ","incidentId":null,"publicView":true,"startDate":"2025-10-21T14:48:00.000Z","endDate":null,"createdAt":"2025-10-22T01:49:54.286Z","updatedAt":"2025-10-22T02:17:32.054Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Security Alert: Phishing Campaign with Malicious links","content":"Salesforce is aware of and closely monitoring a phishing campaign appearing as fraudulent emails from Salesforce with a malicious link to download Remote Monitoring & Management (RMM) software.\n\nOur security teams are working diligently to contain this issue and urge all customers to maintain a high level of vigilance against phishing and social engineering attempts, as these remain frequently used tactics by threat actors. If you receive requests from Salesforce to install RMM software, we recommend you validate its legitimacy with Salesforce Support or architect teams prior to taking action by opening up a ticket through the Salesforce Help portal.\n\nFor guidance and support, please reach out through the Salesforce Help portal. You can also refer to this article for guidance on how to protect your environments from social engineering threats: https://www.salesforce.com/blog/protect-against-social-engineering/. ","createdAt":"2025-10-22T01:49:54.286Z","updatedAt":"2025-10-22T02:17:32.054Z","entryType":"informational_message_created","sourceId":20000227,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000257,"subject":"Security Advisory: Third-Party App Integration Disabled","body":"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident. As a result, organizations will not be able to connect to Salesforce via this app until further notice.\n\nSalesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform.\n\nWe are continuing to work directly with affected customers and Klue. If you need support, please contact: https://help.salesforce.com/s. ","incidentId":null,"publicView":true,"startDate":"2026-06-17T22:20:00.000Z","endDate":"2026-07-17T22:30:00.000Z","createdAt":"2026-06-17T18:22:51.612Z","updatedAt":"2026-06-17T18:22:51.614Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Security Advisory: Third-Party App Integration Disabled","content":"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident. As a result, organizations will not be able to connect to Salesforce via this app until further notice.\n\nSalesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform.\n\nWe are continuing to work directly with affected customers and Klue. If you need support, please contact: https://help.salesforce.com/s. ","createdAt":"2026-06-17T18:22:51.612Z","updatedAt":"2026-06-17T18:22:51.614Z","entryType":"informational_message_created","sourceId":20000257,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]}]