Zero-day tracking

Salesforce zero-day tracking

Salesforce is the customer record. When CISA adds a Salesforce KEV — or a hit on Slack, Heroku, or AWS — the CRM owner needs a briefing the same day, not a six-figure intel PDF.

Watch Salesforce — freeLive SaaS KEV tracker

Why Salesforce is on this watchtower

Most “Salesforce security” tools watch tenant config. This page is narrower: exploited-class CVEs that name Salesforce or a supplier in our graph. You pick Salesforce on a watchlist. We match CISA KEV and critical NVD. Keep Track fans out to parent and cloud-host edges.

What we watch

Suppliers behind Salesforce

Catalog vendors that inherit a hit on Salesforce

Matched KEV and critical CVEs

No catalog matches stored for Salesforce yet. Ingest runs from CISA KEV every six hours. See the live tracker.

Questions

Do you scan our Salesforce org?

No. No OAuth into the tenant, no agent. You name Salesforce. We watch public KEV and critical NVD against that name and the graph.

Will I get every Salesforce CVE?

No. We are exploited-first (CISA KEV) plus recent critical NVD that match the catalog. OpenCVE is the encyclopedia. This is the watchtower.

Add Salesforce to your stack.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing