Our takeParallels Desktop CVE-2026-90894 lets any local Mac user escalate to root. Update to version 27 if you run it yourself; Intel users cannot and remain exposed.Cyber Resilience desk
Sources (4)
- helpnet · helpnet
- hackernews · hackernews
- the420_in · the420_in
- bleeping · bleeping
What this means for you — Security leader:Update Parallels Desktop to version 27 on all Intel and Apple Silicon Macs you manage. The flaw lets any local account escalate to root; the patch is unavailable for Intel systems.
What this means for you — Lean IT orgs:If you run Parallels Desktop on any Mac, update it to version 27 right away. The bug lets any normal user on the machine become root; Intel Macs cannot get the fix.
What this means for you — MSP:Check every client Mac running Parallels Desktop and upgrade to version 27 where possible. The local-to-root flaw cannot be patched on Intel hardware, so note those systems.
What this means for you — Researcher:Review and test the ParaShells PoC on your macOS research systems. The CVE-2026-90894 flaw is corroborated and the patch is unavailable for Intel Macs.