High 7.8
CVE-2026-90894
Parallels Desktop Local Privilege Escalation Vulnerability (CVE-2026-90894)
Vendor / product: Parallels Desktop for Mac
Event date: 2026-09-13
Public PoC: Yes
First tracked by RiskWire: 2026-09-16
Sources & citations (3)
- Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) helpnetsecurity.com · 2026-09-16
- Parallels Desktop Vulnerability Lets Non-Admin Mac Users Execute Code as Root cybersecuritynews.com · 2026-09-16
- Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access gbhackers.com · 2026-09-16
References
See CVE-2026-90894 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →