PatchSiren

Parallels CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Parallels CVE published 2026-09-14

CVE-2026-90894

A local privilege escalation vulnerability exists in Parallels Desktop due to improper validation of user input when handling tar archives. The vulnerability is caused by the use of a world-writable socket and the acceptance of peer credentials without proper validation. This allows local attackers to potentially elevate privileges and access sensitive data. System administrators and security teams should [truncated]

HIGH Parallels CVE published 2026-08-20

CVE-2026-18262

The CVE-2026-18262 vulnerability, known as Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability, allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists [truncated]

HIGH Parallels CVE published 2026-08-20

CVE-2026-13121

The Parallels RAS Client RDP Backend Service contains a vulnerability that allows for local privilege escalation due to an exposed dangerous function. This vulnerability, tracked as CVE-2026-13121, requires an attacker to first execute low-privileged code on the target system. The affected product is Parallels RAS Client. Defenders should verify the presence of affected installations and review the vendor [truncated]