Parallels Desktop 27 security update for CVE-2026-90894
Security Patch Release
Summary
Hide ▲
Show ▼
Parallels Desktop 27.0.0 is the fixed release for CVE-2026-90894, closing a local root flaw in Parallels Desktop for Mac. Builds on 26.x remain on the affected line, and Intel Macs cannot install version 27. The patch matters because the flaw lets an ordinary local account reach root on the host Mac.
Related Happenings
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Isolated-vm security fixes for sandbox escape flaw
Security Patch Release
H score16
First: 20.08.2026 16:48
Last: 20.08.2026 16:48
Sources 1
About this happening:
Security fixes for isolated-vm now close a sandbox escape flaw in affected releases, reducing the risk of host memory corruption and potential host RCE. The patch...
Isolated-vm security fixes for sandbox escape flaw
Security Patch ReleaseAbout this happening: Security fixes for isolated-vm now close a sandbox escape flaw in affected releases, reducing the risk of host memory corruption and potential host RCE. The patch...
Apple macOS security update for CVE-2026-65400
Security Patch Release
H score89
First: 14.08.2026 17:59
Last: 14.08.2026 17:59
Sources 1
About this happening:
Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases, closing a Screen Sharing authentication bypass that could let network attackers...
Apple macOS security update for CVE-2026-65400
Security Patch ReleaseAbout this happening: Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases, closing a Screen Sharing authentication bypass that could let network attackers...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Timeline
-
16.09.2026 16:14 2 articles · 2h ago
Parallels Desktop 27.0.0 is identified as the fixed build for CVE-2026-90894
Mitigation Patch UpdateJFrog places the fix for CVE-2026-90894 in Parallels Desktop 27.0.0 on 1 September 2026, while Parallels' release notes place 27.0.0 on 25 August 2026 and 27.0.1 on 1 September 2026. The fixed line is Parallels Desktop 27, which Intel Macs cannot install, and JFrog says hosts that stay on 26.x do not have the extract change.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
-
16.09.2026 16:14 1 articles · 2h ago
JFrog publishes ParaShells findings on CVE-2026-90894
Initial DisclosureJFrog published ParaShells and described CVE-2026-90894 in Parallels Desktop for Mac as a local flaw that lets a non-admin local account run code as root on the host Mac. JFrog demonstrated the issue on Parallels Desktop 26.4.0 (build 57513), rated it 7.8 out of 10, and said Parallels had not published a statement about the vulnerability.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14