{"key":"NA135","location":"NA","environment":"production","releaseVersion":"Spring '24 Patch 17.3","releaseNumber":"248.17.3","status":"OK","isActive":false,"createdAt":"2019-06-22T01:23:40.809Z","updatedAt":"2025-04-17T17:05:47.207Z","city":"","stateName":"","stateCode":"","countryName":"","countryCode":"","maintenanceWindow":"Saturdays 07:00 PM - 11:00 PM PST","Services":[{"key":"analytics","order":10,"isCore":false},{"key":"B2B2CCommerce","order":1400,"isCore":false},{"key":"B2BCommerce","order":1300,"isCore":false},{"key":"Communities","order":200,"isCore":false},{"key":"coreService","order":1,"isCore":true},{"key":"CPQandBilling","order":100,"isCore":false},{"key":"Customer360Audiences","order":500,"isCore":false},{"key":"EinsteinBots","order":110,"isCore":false},{"key":"liveAgent","order":20,"isCore":false},{"key":"SalesforceCMS","order":1200,"isCore":false},{"key":"SALESFORCEORDERMANAGEMENT","order":1210,"isCore":false},{"key":"SalesforceUnifiedMessaging","order":1450,"isCore":false},{"key":"search","order":5,"isCore":false},{"key":"ServiceCloudMessagingChannels","order":1500,"isCore":false},{"key":"ServiceCloudVoice","order":600,"isCore":false}],"Products":[{"key":"Salesforce_Services","order":0,"isActive":true,"name":"Salesforce Services","altDisplayName":"Sales and Service","url":"/products/Salesforce_Services"}],"Incidents":[],"Tags":[],"GeneralMessages":[{"id":20000244,"subject":"Security Advisory: Protecting Experience Cloud Sites from Guest User Misconfigurations ","body":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity. These attempts are focused on customer configuration settings that, if not properly secured, may increase exposure.\n\nWe encourage customers to review their Experience Cloud guest user settings and take immediate recommended actions. For additional details and steps to help protect your org, please see our blog: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/","incidentId":null,"publicView":true,"startDate":"2026-03-08T04:00:00.000Z","endDate":null,"createdAt":"2026-03-07T23:06:36.591Z","updatedAt":"2026-03-07T23:07:25.213Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Update","content":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nWe have identified additional guidance for customers to help protect their orgs. Please see our updated blog for recommended actions: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity.","createdAt":"2026-03-12T20:20:56.359Z","updatedAt":"2026-03-12T20:20:56.361Z","entryType":"informational_message_update","sourceId":20000406,"sourceType":"update"},{"title":"Security Advisory: Protecting Experience Cloud Sites from Guest User Misconfigurations ","content":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity. These attempts are focused on customer configuration settings that, if not properly secured, may increase exposure.\n\nWe encourage customers to review their Experience Cloud guest user settings and take immediate recommended actions. For additional details and steps to help protect your org, please see our blog: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/","createdAt":"2026-03-07T23:06:36.591Z","updatedAt":"2026-03-07T23:07:25.213Z","entryType":"informational_message_created","sourceId":20000244,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000406,"message":"Salesforce is actively monitoring threat activity targeting public-facing Experience Cloud sites, including attempts to take advantage of overly permissive guest user configurations.\n\nWe have identified additional guidance for customers to help protect their orgs. Please see our updated blog for recommended actions: https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/\n\nAt this time, we have not identified any vulnerability inherent to the Salesforce platform associated with this activity.","createdAt":"2026-03-12T20:20:56.359Z","updatedAt":"2026-03-12T20:20:56.361Z","GeneralMessageId":20000244}]},{"id":20000224,"subject":"Security Advisory: Ongoing Response to Social Engineering Threats","body":"We are aware of recent extortion attempts by threat actors, which we have investigated in partnership with external experts and authorities. Our findings indicate these attempts relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support. At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.\nOur security teams are actively working to protect customer environments and data, providing guidance and support. Customers identified as potentially affected have been notified directly. If you have not received a notification, we currently have no evidence suggesting any impact to your account. We continue to monitor the situation closely and encourage customers to remain vigilant against phishing and social engineering attempts, which remain common tactics used by threat actors.\n\nFor guidance, please review our blog post (https://www.salesforce.com/blog/protect-against-social-engineering), knowledge article (https://help.salesforce.com/s/articleView?id=005226734&type=1), and reach out through the Salesforce Help portal if you need support.","incidentId":null,"publicView":true,"startDate":"2025-10-02T14:50:00.000Z","endDate":null,"createdAt":"2025-10-02T15:58:29.023Z","updatedAt":"2025-10-17T11:49:26.040Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Update","content":"Salesforce is monitoring social engineering campaigns targeting third-party identity providers (IdPs) across the industry. In these attacks, threat actors use fraudulent login pages or impersonate IT support through voice calls to steal credentials or MFA codes, or to trick users into authorizing malicious connected apps. If an IdP account is compromised, attackers may attempt to access connected applications.\n\nPlease note this issue does not stem from a vulnerability inherent to Salesforce; these attacks rely on social engineering and deceptive authentication prompts.\n\nOur security teams are actively working to protect customers and have notified potentially affected accounts. For guidance and mitigations, please review our blog post (https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/) and knowledge article (https://help.salesforce.com/s/articleView?language=en_US&id=005226734&type=1). For support, contact Salesforce Customer Support via https://help.salesforce.com/s/?language=en_US.","createdAt":"2026-01-30T15:58:12.170Z","updatedAt":"2026-01-30T15:58:12.172Z","entryType":"informational_message_update","sourceId":20000402,"sourceType":"update"},{"title":"Security Advisory: Ongoing Response to Social Engineering Threats","content":"We are aware of recent extortion attempts by threat actors, which we have investigated in partnership with external experts and authorities. Our findings indicate these attempts relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support. At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology.\nOur security teams are actively working to protect customer environments and data, providing guidance and support. Customers identified as potentially affected have been notified directly. If you have not received a notification, we currently have no evidence suggesting any impact to your account. We continue to monitor the situation closely and encourage customers to remain vigilant against phishing and social engineering attempts, which remain common tactics used by threat actors.\n\nFor guidance, please review our blog post (https://www.salesforce.com/blog/protect-against-social-engineering), knowledge article (https://help.salesforce.com/s/articleView?id=005226734&type=1), and reach out through the Salesforce Help portal if you need support.","createdAt":"2025-10-02T15:58:29.023Z","updatedAt":"2025-10-17T11:49:26.040Z","entryType":"informational_message_created","sourceId":20000224,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[{"id":20000402,"message":"Salesforce is monitoring social engineering campaigns targeting third-party identity providers (IdPs) across the industry. In these attacks, threat actors use fraudulent login pages or impersonate IT support through voice calls to steal credentials or MFA codes, or to trick users into authorizing malicious connected apps. If an IdP account is compromised, attackers may attempt to access connected applications.\n\nPlease note this issue does not stem from a vulnerability inherent to Salesforce; these attacks rely on social engineering and deceptive authentication prompts.\n\nOur security teams are actively working to protect customers and have notified potentially affected accounts. For guidance and mitigations, please review our blog post (https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/) and knowledge article (https://help.salesforce.com/s/articleView?language=en_US&id=005226734&type=1). For support, contact Salesforce Customer Support via https://help.salesforce.com/s/?language=en_US.","createdAt":"2026-01-30T15:58:12.170Z","updatedAt":"2026-01-30T15:58:12.172Z","GeneralMessageId":20000224}]},{"id":20000259,"subject":"Marketing Cloud MCP Connectivity Issues","body":"Issue: We’re aware of an issue which started at approximately 13:20 UTC that is impacting Marketing Cloud MCP services. \n\nImpact: Customers attempting to utilize the service will observe connection failures. ","incidentId":null,"publicView":true,"startDate":"2026-07-24T13:20:00.000Z","endDate":"2026-07-24T19:28:00.000Z","createdAt":"2026-07-24T17:47:07.220Z","updatedAt":"2026-07-24T19:51:07.044Z","externalId":"93287151","isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"productSpecific","status":"Resolved","timeline":[{"title":"Update","content":"At 19:28 UTC, we have resolved this issue affecting access to the Marketing Cloud Engagement MCP service. We identified that the issue was triggered by the decommission of a related service, which removed a shared outbound access. We resolved the issue by redeploying the outbound access configuration to all affected instances.\n\nWe apologize for how you and your business may have been affected by this incident. We will thoroughly investigate the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-24T19:51:07.041Z","updatedAt":"2026-07-24T19:51:07.042Z","entryType":"informational_message_update","sourceId":20000447,"sourceType":"update"},{"title":"Update","content":"We continue to work towards mitigation. At this time we don’t have any additional updates to share.\n\nWe'll provide an update in 60 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T19:17:39.841Z","updatedAt":"2026-07-24T19:17:39.844Z","entryType":"informational_message_update","sourceId":20000446,"sourceType":"update"},{"title":"Update","content":"We’ve identified that a policy configuration change blocked traffic to service hosts. To mitigate this issue, we’re preparing to redeploy the last known-good policy to reestablish connections.\n\nWe'll provide an update in 30 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T18:39:10.350Z","updatedAt":"2026-07-24T18:39:10.352Z","entryType":"informational_message_update","sourceId":20000445,"sourceType":"update"},{"title":"Marketing Cloud MCP Connectivity Issues","content":"Issue: We’re aware of an issue which started at approximately 13:20 UTC that is impacting Marketing Cloud MCP services. \n\nImpact: Customers attempting to utilize the service will observe connection failures. ","createdAt":"2026-07-24T17:47:07.220Z","updatedAt":"2026-07-24T19:51:07.044Z","entryType":"informational_message_created","sourceId":20000259,"sourceType":"message"}],"productKeys":["Marketing_Cloud"],"InformationalMessageUpdates":[{"id":20000445,"message":"We’ve identified that a policy configuration change blocked traffic to service hosts. To mitigate this issue, we’re preparing to redeploy the last known-good policy to reestablish connections.\n\nWe'll provide an update in 30 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T18:39:10.350Z","updatedAt":"2026-07-24T18:39:10.352Z","GeneralMessageId":20000259},{"id":20000446,"message":"We continue to work towards mitigation. At this time we don’t have any additional updates to share.\n\nWe'll provide an update in 60 minutes or sooner if additional information becomes available.","createdAt":"2026-07-24T19:17:39.841Z","updatedAt":"2026-07-24T19:17:39.844Z","GeneralMessageId":20000259},{"id":20000447,"message":"At 19:28 UTC, we have resolved this issue affecting access to the Marketing Cloud Engagement MCP service. We identified that the issue was triggered by the decommission of a related service, which removed a shared outbound access. We resolved the issue by redeploying the outbound access configuration to all affected instances.\n\nWe apologize for how you and your business may have been affected by this incident. We will thoroughly investigate the incident, confirming the technical trigger, the underlying cause, and preventive action to avoid a repeat in the future.","createdAt":"2026-07-24T19:51:07.041Z","updatedAt":"2026-07-24T19:51:07.042Z","GeneralMessageId":20000259}]},{"id":10001498,"subject":"U.S., EU, and UK Regulations on Software Provision to Russia","body":"Salesforce takes its sanctions and export control obligations seriously, and we require our customers and partners to do the same. Under current United States, European Union, and United Kingdom sanctions, the provision of enterprise management software to individuals or entities in Russia is prohibited. \n\nUntil further notice, we expect our customers and partners will not provide access to Salesforce products and services to their users or affiliates in Russia without appropriate legal authorization. Salesforce may implement technical access controls to support compliance with applicable laws, including as per compliance with OFAC’s Determination Pursuant to Section 1(a)(ii) of Executive Order 14071, European Union Council Regulation 2023/2878, and the United Kingdom Russia (Sanctions) (EU Exit) (Amendment) Regulations 2025.\n\nIf your organization requires access to Salesforce products or services in Russia, please contact your Salesforce account team to discuss our exceptions process.\n","incidentId":null,"publicView":true,"startDate":"2025-04-22T17:12:00.000Z","endDate":null,"createdAt":"2025-04-22T17:13:23.193Z","updatedAt":"2025-10-07T17:48:18.615Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"U.S., EU, and UK Regulations on Software Provision to Russia","content":"Salesforce takes its sanctions and export control obligations seriously, and we require our customers and partners to do the same. Under current United States, European Union, and United Kingdom sanctions, the provision of enterprise management software to individuals or entities in Russia is prohibited. \n\nUntil further notice, we expect our customers and partners will not provide access to Salesforce products and services to their users or affiliates in Russia without appropriate legal authorization. Salesforce may implement technical access controls to support compliance with applicable laws, including as per compliance with OFAC’s Determination Pursuant to Section 1(a)(ii) of Executive Order 14071, European Union Council Regulation 2023/2878, and the United Kingdom Russia (Sanctions) (EU Exit) (Amendment) Regulations 2025.\n\nIf your organization requires access to Salesforce products or services in Russia, please contact your Salesforce account team to discuss our exceptions process.\n","createdAt":"2025-04-22T17:13:23.193Z","updatedAt":"2025-10-07T17:48:18.615Z","entryType":"informational_message_created","sourceId":10001498,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000246,"subject":"How Salesforce is preparing for the frontier AI threat landscape","body":"Anthropic’s announcement of Claude Mythos underscores a reality Salesforce has been preparing for: increasingly capable frontier AI models will continue to accelerate the evolution of the cybersecurity landscape.\n\nOur security teams are continuously evaluating how frontier models like Mythos may change attacker and defender capabilities, and we are applying those insights to strengthen our security posture and guide continued enhancements across our environment.\n\nWe view this as an acceleration of work already underway, not a departure from it. Salesforce has long invested in automation and AI to help identify risk, strengthen defenses, and support the trust our customers place in us.\n\nTrust remains our #1 value, and we remain focused on helping protect our customers’ data in a rapidly evolving threat environment.","incidentId":null,"publicView":true,"startDate":"2026-04-14T06:23:00.000Z","endDate":null,"createdAt":"2026-04-13T23:24:55.319Z","updatedAt":"2026-04-13T23:24:55.322Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"How Salesforce is preparing for the frontier AI threat landscape","content":"Anthropic’s announcement of Claude Mythos underscores a reality Salesforce has been preparing for: increasingly capable frontier AI models will continue to accelerate the evolution of the cybersecurity landscape.\n\nOur security teams are continuously evaluating how frontier models like Mythos may change attacker and defender capabilities, and we are applying those insights to strengthen our security posture and guide continued enhancements across our environment.\n\nWe view this as an acceleration of work already underway, not a departure from it. Salesforce has long invested in automation and AI to help identify risk, strengthen defenses, and support the trust our customers place in us.\n\nTrust remains our #1 value, and we remain focused on helping protect our customers’ data in a rapidly evolving threat environment.","createdAt":"2026-04-13T23:24:55.319Z","updatedAt":"2026-04-13T23:24:55.322Z","entryType":"informational_message_created","sourceId":20000246,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000227,"subject":"Security Alert: Phishing Campaign with Malicious links","body":"Salesforce is aware of and closely monitoring a phishing campaign appearing as fraudulent emails from Salesforce with a malicious link to download Remote Monitoring & Management (RMM) software.\n\nOur security teams are working diligently to contain this issue and urge all customers to maintain a high level of vigilance against phishing and social engineering attempts, as these remain frequently used tactics by threat actors. If you receive requests from Salesforce to install RMM software, we recommend you validate its legitimacy with Salesforce Support or architect teams prior to taking action by opening up a ticket through the Salesforce Help portal.\n\nFor guidance and support, please reach out through the Salesforce Help portal. You can also refer to this article for guidance on how to protect your environments from social engineering threats: https://www.salesforce.com/blog/protect-against-social-engineering/. ","incidentId":null,"publicView":true,"startDate":"2025-10-21T14:48:00.000Z","endDate":null,"createdAt":"2025-10-22T01:49:54.286Z","updatedAt":"2025-10-22T02:17:32.054Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Active","timeline":[{"title":"Security Alert: Phishing Campaign with Malicious links","content":"Salesforce is aware of and closely monitoring a phishing campaign appearing as fraudulent emails from Salesforce with a malicious link to download Remote Monitoring & Management (RMM) software.\n\nOur security teams are working diligently to contain this issue and urge all customers to maintain a high level of vigilance against phishing and social engineering attempts, as these remain frequently used tactics by threat actors. If you receive requests from Salesforce to install RMM software, we recommend you validate its legitimacy with Salesforce Support or architect teams prior to taking action by opening up a ticket through the Salesforce Help portal.\n\nFor guidance and support, please reach out through the Salesforce Help portal. You can also refer to this article for guidance on how to protect your environments from social engineering threats: https://www.salesforce.com/blog/protect-against-social-engineering/. ","createdAt":"2025-10-22T01:49:54.286Z","updatedAt":"2025-10-22T02:17:32.054Z","entryType":"informational_message_created","sourceId":20000227,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]},{"id":20000257,"subject":"Security Advisory: Third-Party App Integration Disabled","body":"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident. As a result, organizations will not be able to connect to Salesforce via this app until further notice.\n\nSalesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform.\n\nWe are continuing to work directly with affected customers and Klue. If you need support, please contact: https://help.salesforce.com/s. ","incidentId":null,"publicView":true,"startDate":"2026-06-17T22:20:00.000Z","endDate":"2026-07-17T22:30:00.000Z","createdAt":"2026-06-17T18:22:51.612Z","updatedAt":"2026-06-17T18:22:51.614Z","externalId":null,"isVisibleWhenClosed":false,"isVisible":true,"informationalMessageType":"informationalMessage","status":"Resolved","timeline":[{"title":"Security Advisory: Third-Party App Integration Disabled","content":"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident. As a result, organizations will not be able to connect to Salesforce via this app until further notice.\n\nSalesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce. This issue is limited to Klue’s app connection and does not arise from a vulnerability within the Salesforce platform.\n\nWe are continuing to work directly with affected customers and Klue. If you need support, please contact: https://help.salesforce.com/s. ","createdAt":"2026-06-17T18:22:51.612Z","updatedAt":"2026-06-17T18:22:51.614Z","entryType":"informational_message_created","sourceId":20000257,"sourceType":"message"}],"productKeys":[],"InformationalMessageUpdates":[]}],"Maintenances":[]}