Effective Oct 1, 2025, Salesforce is replacing email-based submissions with a new, more efficient web form for reporting vulnerabilities. This new portal is designed to streamline the process, enabling faster resolution times and improved tracking of your reports. The previous email address will remain active temporarily to ensure a smooth transition.
What's Changing?
Starting October 1, 2025 we will be transitioning from our current email-based intake system to a new web-based form for submitting product vulnerability reports. This means that instead of sending emails to security@salesforce.com, you will now submit your reports through our dedicated online portal.
To report all other other security concerns, including phishing attempts and inappropriate content, please visit https://security.salesforce.com/contact.
Why the Change?
This transition to a web-based form is designed to enhance the overall efficiency and effectiveness of our vulnerability management process. Here are the key benefits:
1. Faster Resolution Times: The new portal ensures that all necessary information is captured upfront, reducing delays caused by incomplete initial submissions.
2. Improved Tracking and Analysis: The form allows for better identification and tracking of multiple vulnerabilities within a single report, enabling more accurate and efficient triage and analysis.
What You Need to Do
- Starting October 1, 2025, please begin using the following link to submit your product vulnerability reports: https://www.sfdc.co/SubmitVuln
- The email address security@salesforce.com will continue to accept vulnerability submissions until November 15, 2025, to allow time for customers to adjust their applicable processes
Support and Assistance
We are committed to making this transition as smooth as possible for you. If you have any questions or need assistance with the new portal, please do not hesitate to reach out via the security@salesforce.com email address.
We appreciate your understanding and cooperation as we make this important change to better serve you. Thank you for your continued partnership with Salesforce.
005132095

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.