Salesforce Outage, 16 September 2026: What Happened and What to Do
On 16 September 2026 Salesforce had a major service disruption across many Hyperforce instances in all regions. Salesforce's status record runs it from 07:50 to 15:26 UTC (7:50 pm to 3:26 am NZST), attributes it to increased load on a core system component, and promises a full investigation. No root cause analysis has been published yet.
Everything below is as at 18 September 2026 and comes from Salesforce's incident record unless another source is linked. NZ times are NZST, 12 hours ahead of UTC under the Time Act 1974; daylight saving starts on 27 September 2026.
What happened in the Salesforce outage on 16 September 2026?
Customers on affected instances had "severe delays, intermittent errors, or an inability to access some services" for about seven and a half hours, and some could not log support cases through the Help portal. The public status API records it as a service disruption of major severity.
It landed during Dreamforce, as Salesforce Ben and CIO both reported. Every row below is Salesforce's own update, condensed.
| Time (UTC) | Time (NZST) | What Salesforce said | Source |
|---|---|---|---|
| 07:50 | 7:50 pm Wed 16 Sep | Recorded start of impact | Trust |
| 08:45 | 8:45 pm | First update: "multiple instances across all regions"; some customers cannot submit support cases | Trust |
| 09:10 | 9:10 pm | Requests are stalling while waiting on "an internal login service" | Trust |
| 09:57 | 9:57 pm | Suspects "an external dependency failure that's impacting the legacy login server"; blocks an API endpoint as mitigation; the third-party infrastructure provider reports no issues | Trust |
| 10:18 | 10:18 pm | "One of our core system components experienced increased load, which limited its capacity to process requests." | Trust |
| 10:56 | 10:56 pm | Fix validated on a test instance; fleetwide rollout follows, region by region | Trust |
| 13:13 | 1:13 am Thu 17 Sep | Rollout did not fully complete on some instances; fix reapplied; some customers may need to clear cached data or restart their session | Trust |
| 14:00 | 2:00 am | Reports of scheduled jobs not running as expected; instances with no impact start being removed from the list | Trust |
| 15:39 | 3:39 am | Remaining impact is "a subset of Hyperforce instances"; first-party environments were not impacted | Trust |
| 18:59 | 6:59 am | Declared resolved "as of 15:26 UTC"; full investigation promised | Trust |
| 17:16, 17 Sep | 5:16 am Fri 18 Sep | Follow-up: "sandboxes were not impacted" and have been removed from the incident's instance list | Trust |
What caused the Salesforce outage?
Salesforce's working explanation is that a core system component came under increased load, which limited its capacity to process requests. That describes the mechanism, not the root cause: what triggered the load has not been published.
The explanation moved during the incident, as the table shows: an internal login service, then a legacy login server with a suspected external dependency, then load on a core component.
The closing update commits Salesforce to a full investigation "establishing the technical trigger, the underlying cause, and preventive action". On earlier incidents Salesforce linked a preliminary root cause analysis, published as a Help article, from the incident page: on incident 13460 in November 2024 that link appeared two days after the incident. Salesforce has given no date for this one. Until it lands, anything more specific about the trigger is guesswork.
Was data lost or breached in the Salesforce outage?
Salesforce has not said either way. As at 18 September 2026 its updates describe a capacity problem, and none of them mentions a security incident, unauthorised access or data loss. None rules them out in so many words either, so we will not.
The practical risk for a small team is missed work. Salesforce acknowledged scheduled jobs not running for some customers and blocked an API endpoint (it did not say which) as a mitigation. For NZ teams the window ran overnight, so check what runs overnight: scheduled jobs, integration syncs, anything that writes to Salesforce through the API.
How do you check whether your Salesforce org was affected?
Find your instance name, then look it up on status.salesforce.com and open its history. Salesforce's instance article gives two routes: Setup, Company Information, the Instance field; or your My Domain name in the status site's search bar. Per the same article, three-letter names such as GBR10 are Hyperforce and two-letter names such as AP0 are first-party infrastructure, which Salesforce said was not impacted.
As at 18 September 2026 the incident record lists 595 instances, after Salesforce removed sandboxes and instances it found were not impacted. The list includes instances starting AUS, alongside USA, IND, GBR, DEU and others. Check your own; do not assume from your region.
Two Setup pages then show what it did to you. Login History keeps six months of login attempts. Scheduled Jobs lists scheduled Apex jobs, reporting snapshots and dashboard refreshes with their start and next-run times.
One change to know: Salesforce is moving status to My Trust Center at my.trust.salesforce.com. Its FAQ says it already supports production Agentforce Sales and Agentforce Service, and that "Existing subscriptions on Salesforce Status don't automatically transfer."
Does Salesforce compensate customers for downtime?
Not under its standard public contract. Salesforce's Main Services Agreement, "last updated on September 1, 2026", contains no uptime percentage, and the terms "service level" and "service credit" do not appear in it.
Section 2.1 promises to "use commercially reasonable efforts to make the online Purchased Services available 24 hours a day, 7 days a week", except for planned downtime and circumstances beyond Salesforce's reasonable control. Under section 8.2 the exclusive remedies for a warranty breach are termination and a refund of prepaid fees for the remaining term. Section 10 caps liability at twelve months of fees and excludes lost profits and business interruption. For customers in New Zealand or Australia the contracting entity is SFDC Australia Pty Ltd, under New South Wales law.
The incident updates carry an apology and no mention of credits. Your signed order form or negotiated terms may differ, so read your own. This is a summary, not legal advice.
How should a small team prepare for the next Salesforce outage?
Decide in advance how you will find out, what you will work from and who tells the team. None of that needs new software, and not every popular precaution would have helped on 16 September.
| Preparation | What it gives you | Would it have helped on 16 September? | Source |
|---|---|---|---|
| Trust notifications for your instance | Email or SMS when your instance has an incident or maintenance | Yes: you know it is not your password or your internet | Subscribe to Trust Notifications |
| Instance and My Domain name written down | A 30-second status lookup | Yes | My Domain status lookup |
| Offline copy of today's critical lists | Call list, jobs or bookings in a spreadsheet | Yes: this is what keeps work moving | Export a Report |
| Data Export, weekly or monthly | A zip of CSV files of your data | Partly: readable data if already downloaded, not a working CRM | Export Backup Data |
| Backup and Recover (paid) | "Automated Daily backups" and restore | No: it protects data, not availability | Product page |
| Admin login that bypasses SSO | Admin access when your identity provider is down | No: this fault was inside Salesforce. It covers an identity provider outage | Require SSO article |
Notifications. Salesforce's incident communications article sets an objective "to post to Trust within 10 minutes of becoming aware" of a critical incident, with updates at least every 30 minutes. Informational Messages are a separate subscription. Subscribe two people.
Data Export. Weekly export is listed for Enterprise, Performance and Unlimited Editions, monthly for all editions except Database.com. Zip files "are deleted 48 hours after the email is sent (not including weekends)", and the Data Export FAQ says "There is no SLA for Data Exports." Diarise the download.
SSO. Salesforce recommends "that you don't require SSO for Salesforce admins" so they can respond to SSO outages. Keep MFA on that account; see our security settings checklist.
Integrations. Ask each vendor one question: when Salesforce returns errors for hours, do you queue and retry, or drop the record? If you are already asking vendors about the Winter '27 integration changes, add it to that conversation.
A comms template. Three lines, written now: Salesforce has a confirmed disruption, so it is not your password; do not reset anything or enter data twice; work from the offline list until the next update.
Who should not over-react to this outage?
Most small teams. One disruption of this length does not justify replatforming, and nothing published so far points to data loss.
- Do not move CRM over this. A migration carries its own risks; our data migration guide shows what is involved. Weigh that against hours of disruption.
- Do not buy backup in a panic. Backup and Recover has no public price; its product page says pricing varies by customer. A very small org can start with the built-in export and an offline list. Paid backup earns its place when integrations write large volumes, a regulator or funder expects it, or a bad bulk update is a realistic risk.
- Skip the clean-up if your instance was not on the list. Salesforce removed unaffected instances and said first-party environments were not impacted.
What should a small business do this week?
- Look up your instance and read its history for 16 September.
- Subscribe two people to Trust notifications and Informational Messages, and to My Trust Center if your org appears there.
- Check the window. Scheduled Jobs, Login History and each integration's log from 7:50 pm Wednesday to 3:26 am Thursday NZST. Re-run what failed.
- Schedule Data Export and diarise the download inside 48 hours.
- Export the two or three reports you could not work without and store them where the team can reach them offline.
- Confirm one admin can log in without SSO, with MFA on.
- Write the comms template and set a reminder to read the root cause analysis when it is published.
No admin to own this list? That is the kind of gap a fractional admin or a managed services arrangement is for.
Ask a Salesforce question
Nobody owns Salesforce continuity on your team?
SAASKOOL fractional admins, developers and architects start at NZ$99/hr + GST, by the hour or on a monthly retainer, with no long-term contract. Tell us what is piling up and we will reply within 1 business day with the right role and engagement model.
Frequently Asked Questions
Is Salesforce down right now? Check status.salesforce.com: search your My Domain name or instance name and read its current status and history. The 16 September 2026 disruption was declared resolved the same day, with recovery recorded at 15:26 UTC. If your instance shows green and you still cannot log in, look at your own SSO, network or password first.
What caused the Salesforce outage on 16 September 2026? Salesforce says one of its core system components experienced increased load, which limited its capacity to process requests. Earlier updates pointed to an internal login service and a legacy login server. As at 18 September 2026 no root cause analysis is published; Salesforce has promised a full investigation.
Was customer data lost or breached in the Salesforce outage? Salesforce has not said either way. As at 18 September 2026 its incident updates describe a capacity problem and do not mention a security incident, unauthorised access or data loss. They do mention scheduled jobs not running as expected for some customers, so check your overnight jobs and integrations.
Does Salesforce pay compensation or service credits for downtime? Not under its public Main Services Agreement, last updated 1 September 2026. That agreement promises commercially reasonable efforts to keep services available 24 hours a day, 7 days a week, and contains no uptime percentage and no service credit clause. Your own order form may differ, so read it.
Do I need a paid Salesforce backup tool after this outage? Not because of this outage. Backup protects against lost or corrupted data, and nothing published so far says data was lost. A backup also does not give you a working CRM while Salesforce is unavailable. For a very small org, the built-in Data Export plus an offline copy of key lists is a reasonable start.
SAASKOOL is a New Zealand Salesforce partner. If you want a second pair of eyes on your continuity setup, start with our free Salesforce health check.
Tags
Related Articles
Dreamforce 2026 Announcements: What Matters for Small Business
Dreamforce 2026 for small teams: AIforce, Slackforce, Koa and the new agents, with what is GA, beta or roadmap, editions, stated prices and what to do now.
Read more Salesforce GuidesSalesforce Core, Advanced and Max Editions: NZ Small Business Guide
Salesforce Core, Advanced and Max editions for NZ small businesses: list prices, Flex Credits, what happens to Enterprise Edition and who can ignore it.
Read more Salesforce GuidesHow to Connect Claude or ChatGPT to Salesforce: What Works Today and What Your Edition Allows
Connect Claude or ChatGPT to Salesforce through the hosted MCP servers: setup steps, edition gating, Claudeforce beta status, permissions, training and cost.
Read more