VulnerabilitiesApr 15, 2026
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
Microsoft and Salesforce patch prompt injection flaws in AI agents that could leak sensitive data.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Microsoft Copilot and Salesforce Agentforce contained prompt injection vulnerabilities that could allow external attackers to extract sensitive data from these AI agent platforms. Both vendors have released patches to address the flaws, which highlight the emerging security risks in AI agent deployments and the need for robust input validation in AI systems.
Entities
Microsoft (vendor)Salesforce (vendor)Microsoft Copilot (product)Salesforce Agentforce (product)AI agents (technology)