Find notable cyber news and cases, enriched with sources, timelines, and signals.

Parallels Desktop 27 security update for CVE-2026-90894

Security Patch Release
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Parallels Desktop 27.0.0 is the fixed release for CVE-2026-90894, closing a local root flaw in Parallels Desktop for Mac. Builds on 26.x remain on the affected line, and Intel Macs cannot install version 27. The patch matters because the flaw lets an ordinary local account reach root on the host Mac.

Related Happenings

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
H score43 First: 27.08.2026 00:33 Last: 27.08.2026 00:33 Sources 1

About this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...

Isolated-vm security fixes for sandbox escape flaw

Security Patch Release
H score16 First: 20.08.2026 16:48 Last: 20.08.2026 16:48 Sources 1

About this happening: Security fixes for isolated-vm now close a sandbox escape flaw in affected releases, reducing the risk of host memory corruption and potential host RCE. The patch...

Apple macOS security update for CVE-2026-65400

Security Patch Release
H score89 First: 14.08.2026 17:59 Last: 14.08.2026 17:59 Sources 1

About this happening: Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases, closing a Screen Sharing authentication bypass that could let network attackers...

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Adobe security patch release for CVE-2026-71398

Security Patch Release
H score37 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...

Latest development: 12.08.2026 14:13

Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Timeline

  1. 16.09.2026 16:14 2 articles · 2h ago

    Parallels Desktop 27.0.0 is identified as the fixed build for CVE-2026-90894

    Mitigation Patch Update

    JFrog places the fix for CVE-2026-90894 in Parallels Desktop 27.0.0 on 1 September 2026, while Parallels' release notes place 27.0.0 on 25 August 2026 and 27.0.1 on 1 September 2026. The fixed line is Parallels Desktop 27, which Intel Macs cannot install, and JFrog says hosts that stay on 26.x do not have the extract change.

    Show sources
  2. 16.09.2026 16:14 1 articles · 2h ago

    JFrog publishes ParaShells findings on CVE-2026-90894

    Initial Disclosure

    JFrog published ParaShells and described CVE-2026-90894 in Parallels Desktop for Mac as a local flaw that lets a non-admin local account run code as root on the host Mac. JFrog demonstrated the issue on Parallels Desktop 26.4.0 (build 57513), rated it 7.8 out of 10, and said Parallels had not published a statement about the vulnerability.

    Show sources