{
 "updated": "2026-09-25",
 "source": "https://sfupdates.com/release-updates/",
 "license": "CC-BY 4.0",
 "items": [
  {
   "name": "Restrict the OAuth 2.0 Device Flow to Local External Client Apps",
   "area": "OAuth, security",
   "first_release": "Summer '26",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-11-30",
   "status": "scheduled",
   "summary": "The device flow only works for local External Client Apps with a localhost callback; connected apps using it must migrate.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_security_oauth_device.htm&release=264&type=5"
  },
  {
   "name": "Maintain Your Email Verification Exception",
   "area": "Email, security",
   "first_release": "Winter '27",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-12-01",
   "status": "scheduled",
   "summary": "Orgs whose email verification was disabled by Support must configure an authorized email domain; allowlists are removed at enforcement. Replaces the cancelled Adopt Authorized Email Domains update.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_sales_email_maintain_verfication_exception.htm&release=264&type=5"
  },
  {
   "name": "Assign Use Any API Auth Permission for SOAP login()",
   "area": "API, security",
   "first_release": "Winter '27",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-12-01",
   "status": "scheduled",
   "summary": "Users authenticating through SOAP login() must hold the Use Any API Auth permission; enforced across all orgs from December 1, 2026.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_api_soap_login.htm&release=264&type=5"
  },
  {
   "name": "Republish Your Marketing Cloud Next Landing Pages",
   "area": "Marketing Cloud Next",
   "first_release": "Winter '27",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-10-31",
   "enforce_label": "October 2026",
   "status": "scheduled",
   "summary": "Landing pages published more than six months ago must be republished to move to supported infrastructure.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_mktg_repub_landingpage_ru.htm&release=264&type=5"
  },
  {
   "name": "Update Instanced URLs in API Traffic",
   "area": "API, My Domain",
   "first_release": "Summer '25",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-12",
   "enforce_label": "Phased: sandboxes Oct 22 and Nov 3, 2026; production Jan 12, Jan 26, Mar 2 and Mar 23, 2027",
   "status": "postponed",
   "summary": "API calls must use the My Domain login URL instead of instance URLs such as na139.salesforce.com. Postponed from Spring '26, Summer '26 and Winter '27.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_update_instanced_urls_in_api_traffic.htm&release=264&type=5"
  },
  {
   "name": "Retirement of OAuth 2.0 Username-Password Flow for Connected Apps",
   "area": "OAuth, API, security",
   "first_release": "Spring '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-02-20",
   "status": "postponed",
   "summary": "grant_type=password stops issuing tokens for connected apps; use the web server or client credentials flow. Already blocked in orgs created since Summer '26. Moved from Winter '27 to February 20, 2027.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_security_oauth_unpw.htm&release=264&type=5"
  },
  {
   "name": "OAuth User-Agent and Hybrid User-Agent Flows Retirement",
   "area": "OAuth, security",
   "first_release": "Summer '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-02-20",
   "status": "scheduled",
   "summary": "User-agent and hybrid user-agent flows are retired; move to the web server flow with PKCE. Blocked in orgs created since Winter '27.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_security_oauth_useragent.htm&release=264&type=5"
  },
  {
   "name": "Update Apex Code and Flows for Changed Sharing Recalculation Behavior",
   "area": "Apex, Flow, sharing",
   "first_release": "Spring '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "Some sharing recalculations after group or role changes run asynchronously; Apex and Flows that assume share records exist immediately can break.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_sharing_apex_recalc.htm&release=264&type=5"
  },
  {
   "name": "Remove Non-Public Fields from Custom Object Data in Aura Action Responses",
   "area": "Lightning, Aura",
   "first_release": "Summer '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "Internal system fields are stripped from custom object data returned by Aura server actions.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_lc_rus_remove_nonpublic_fields_ru.htm&release=264&type=5"
  },
  {
   "name": "Enable Accessibility Enhancements for To Do Lists and Lightning Dual Listboxes When Zoom Is Greater Than 200%",
   "area": "Lightning Experience UI",
   "first_release": "Summer '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "WCAG 2.2 reflow behavior for to do lists and dual listboxes at high zoom levels.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_general_accessibility_todo_listboxes_ru_262.htm&release=264&type=5"
  },
  {
   "name": "Render Visualforce Pages as Accessible (Tagged) PDFs",
   "area": "Visualforce",
   "first_release": "Winter '27",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "renderAs=pdf switches to the tagged PDF/UA rendering engine.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_vf_accessible_pdf_ru.htm&release=264&type=5"
  },
  {
   "name": "Salesforce Connect Cross-Org Adapter Legacy Authentication Is Being Retired",
   "area": "Salesforce Connect, integration",
   "first_release": "Winter '27",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "Password and legacy OAuth authentication for the cross-org adapter depend on SOAP login() and are retired; migrate to named credentials.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_sf_connect_xorg_legacy_auth_retiring_ru.htm&release=264&type=5"
  },
  {
   "name": "Salesforce to Salesforce Is Being Retired",
   "area": "Integration, Sales",
   "first_release": "Spring '26",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "Salesforce to Salesforce stops working; could not be enabled since Spring '26 and was unsupported from Summer '26. Replacements: Partner Cloud, Data Cloud One, MuleSoft.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_sales_salesforce_to_salesforce_retiring_ru.htm&release=262&type=5"
  },
  {
   "name": "View Setup Audit Trail Permission to Access Setup Audit Trail",
   "area": "Permissions",
   "first_release": "Winter '27",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "A dedicated permission gates Setup Audit Trail; it is granted automatically where View Setup and Configuration exists.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_setup_audit_trail.htm&release=264&type=5"
  },
  {
   "name": "Conceal Personal Information Fields from Guest Users",
   "area": "Experience Cloud, security",
   "first_release": "Winter '27",
   "enforce_release": "Spring '27",
   "enforce_date": "2027-01-16",
   "enforce_label": "Spring '27 (first production weekend, est. Jan 16, 2027)",
   "status": "scheduled",
   "summary": "A new Guest_PersonalInfo_EPIM field set masks personal information for guest users independently of portal users.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_experiences_conceal_pii_guests.htm&release=264&type=5"
  },
  {
   "name": "SOAP API login() Call in SOAP API Versions 31.0 Through 64.0 Is Being Retired",
   "area": "API, authentication",
   "first_release": "Winter '26",
   "enforce_release": "Summer '27",
   "enforce_date": "2027-05-15",
   "enforce_label": "Summer '27 (first production weekend, est. May 15, 2027)",
   "status": "scheduled",
   "summary": "login() is removed for every SOAP API version; authenticate with OAuth through External Client Apps. A test run is available in Setup.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_api_soap_login_retirement.htm&release=264&type=5"
  },
  {
   "name": "Migrate All Connected Apps to External Client Apps",
   "area": "OAuth, integration",
   "first_release": "Winter '27",
   "enforce_release": "Summer '27",
   "enforce_date": "2027-05-15",
   "enforce_label": "Summer '27 (first production weekend, est. May 15, 2027)",
   "status": "scheduled",
   "summary": "Connected apps keep working but lose support and bug fixes; migrate them from App Manager.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_security_migrate_all_connected_apps.htm&release=264&type=5"
  },
  {
   "name": "Block Apex Anonymous Code Execution from Managed Packages",
   "area": "Apex, packaging, security",
   "first_release": "Summer '26",
   "enforce_release": "Summer '27",
   "enforce_date": "2027-05-15",
   "enforce_label": "Summer '27 (first production weekend, est. May 15, 2027)",
   "status": "scheduled",
   "summary": "Session IDs obtained inside managed packages can no longer run executeAnonymous; namespaces created since Summer '26 are already blocked.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_apex_block_exec_anon_ru.htm&release=262&type=5"
  },
  {
   "name": "Optimize Performance for Revenue Management",
   "area": "Revenue Cloud",
   "first_release": "Winter '27",
   "enforce_release": "Summer '27",
   "enforce_date": "2027-05-15",
   "enforce_label": "Summer '27 (first production weekend, est. May 15, 2027)",
   "status": "scheduled",
   "summary": "The Configuration API is optimized for Product Configurator processing time.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_product_configurator_optimize_performance.htm&release=264&type=5"
  },
  {
   "name": "Switch to a Single Domain Certificate for Your Salesforce Content Delivery Network",
   "area": "CDN, security",
   "first_release": "Summer '24",
   "enforce_release": "Not scheduled",
   "enforce_date": null,
   "enforce_label": "Postponed indefinitely (was Spring '25, then Spring '26)",
   "status": "postponed",
   "summary": "Moves the Salesforce CDN to a single-domain certificate.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=258&type=5"
  },
  {
   "name": "Enforcing No-Argument Constructor on Apex Classes Used for Invocable Action Parameters",
   "area": "Apex, Flow",
   "first_release": "Summer '24",
   "enforce_release": "Not scheduled",
   "enforce_date": null,
   "enforce_label": "Enforcement dropped in Spring '26 (was Summer '26); still recommended",
   "status": "postponed",
   "summary": "Formerly Enforce Permission Requirements Defined on Built-In Apex Classes Used as Inputs.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Enable ICU Locale Formats",
   "area": "Globalization",
   "first_release": "Winter '20",
   "enforce_release": "Not scheduled",
   "enforce_date": null,
   "enforce_label": "No enforcement date announced",
   "status": "postponed",
   "summary": "Replaces Oracle JDK locale formats with ICU formats for dates, times, numbers and currencies.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Enable Accessibility Enhancements for Cards, Docked Containers, Menu Lists, and Panels",
   "area": "Lightning Experience UI",
   "first_release": "Summer '26",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-08-29",
   "enforce_label": "Winter '27",
   "status": "enforced",
   "summary": "WCAG 2.2 resize and reflow behavior above 200% zoom.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_general_accessibility_cards_docked_containers_ru_262.htm&release=264&type=5"
  },
  {
   "name": "Enable Accessibility Enhancements for Date Pickers, Popovers, Bottom Utility Bars, Record Headers",
   "area": "Lightning Experience UI",
   "first_release": "Winter '26",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-08-29",
   "enforce_label": "Winter '27 (postponed from Summer '26)",
   "status": "enforced",
   "summary": "WCAG 2.2 behavior at high zoom for date pickers, popovers, utility bars and record headers.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_general_accessibility_datepicker_recordheaders_ru.htm&release=264&type=5"
  },
  {
   "name": "Enable Accessibility Enhancements for Page Headers and Modal Windows When Zoom Is Greater Than 200%",
   "area": "Lightning Experience UI",
   "first_release": "Summer '25",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-08-29",
   "enforce_label": "Winter '27 (postponed from Spring '26 and Summer '26)",
   "status": "enforced",
   "summary": "WCAG 2.2 behavior for page headers and modals.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_general_accessibility_page_headers_modals_ru.htm&release=264&type=5"
  },
  {
   "name": "Enable Profile Filtering",
   "area": "Permissions, security",
   "first_release": "Summer '26",
   "enforce_release": "Winter '27",
   "enforce_date": "2026-08-29",
   "enforce_label": "Winter '27",
   "status": "enforced",
   "summary": "Users see only their own profile name unless they hold View All Profiles.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_permissions_profile_filtering_enforced.htm&release=264&type=5"
  },
  {
   "name": "Migrate to a Multiple-Configuration SAML Framework",
   "area": "SSO, security",
   "first_release": "Spring '24",
   "enforce_release": "Summer '26",
   "enforce_date": "2026-05-16",
   "enforce_label": "Summer '26 (postponed from Spring '25 and Spring '26)",
   "status": "enforced",
   "summary": "Single-configuration SAML is removed; SSO breaks for orgs that did not migrate.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Salesforce-Managed X (Formerly Twitter) Authentication Provider Retirement",
   "area": "Authentication providers",
   "first_release": "Spring '26",
   "enforce_release": "Summer '26",
   "enforce_date": "2026-05-16",
   "enforce_label": "Summer '26",
   "status": "enforced",
   "summary": "The Salesforce-managed X app is retired; create a custom X app for the auth provider.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Sort Apex Batch Action Results by Request Order",
   "area": "Apex, Flow actions",
   "first_release": "Spring '25",
   "enforce_release": "Summer '26",
   "enforce_date": "2026-05-16",
   "enforce_label": "Summer '26",
   "status": "enforced",
   "summary": "Batch action results are returned in request order instead of errors first.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Use Visualforce PDF Rendering Service with Apex Blob.toPdf()",
   "area": "Apex, Visualforce",
   "first_release": "Spring '26",
   "enforce_release": "Summer '26",
   "enforce_date": "2026-05-16",
   "enforce_label": "Summer '26",
   "status": "enforced",
   "summary": "Blob.toPdf() uses the Visualforce PDF renderer, adding fonts and multibyte support.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=262&type=5"
  },
  {
   "name": "Escape the Label Attribute of apex:inputField Elements to Prevent Cross-Site Scripting",
   "area": "Visualforce, security",
   "first_release": "Spring '23",
   "enforce_release": "Spring '26",
   "enforce_date": "2026-01-17",
   "enforce_label": "Spring '26",
   "status": "enforced",
   "summary": "The label attribute of apex:inputField is escaped to block XSS.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=260&type=5"
  },
  {
   "name": "Update References to Legacy Host Names",
   "area": "My Domain, security",
   "first_release": "Spring '25",
   "enforce_release": "Spring '26",
   "enforce_date": "2026-01-17",
   "enforce_label": "Spring '26 (auto-enabled in Winter '26)",
   "status": "enforced",
   "summary": "Ends the temporary redirection of legacy, non-enhanced Salesforce host names.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=260&type=5"
  },
  {
   "name": "Restrict User Access to Run Flows",
   "area": "Flow, security",
   "first_release": "Winter '24",
   "enforce_release": "Winter '26",
   "enforce_date": "2025-08-30",
   "enforce_label": "Winter '26 (postponed from Winter '25)",
   "status": "enforced",
   "summary": "Users need the Run Flows permission or explicit flow access; the legacy behavior that let every user run every flow ends.",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=258&type=5"
  },
  {
   "name": "Adopt Authorized Email Domains",
   "area": "Email, security",
   "first_release": "Spring '26",
   "enforce_release": "Was Winter '27",
   "enforce_date": null,
   "enforce_label": "Cancelled in Winter '27, replaced by Maintain Your Email Verification Exception",
   "status": "cancelled",
   "summary": "",
   "url": "https://help.salesforce.com/s/articleView?id=release-notes.rn_ru.htm&release=264&type=5"
  }
 ]
}