SecAlerts
P

Parallels

Security Risk Profile

55
/100
medium

Security Risk Score

Comprehensive risk assessment based on 301 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 8, 2006 to present

301
Total CVEs
193
Critical+High
3
Exploited
190
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
190
Critical/High
Risk Level
55/100
medium
⚠️ 3 Active Exploits 1 Zero-Days🆕 108Fresh (<7d)📈 117 in Last 30 Days

Severity Distribution

Critical
22
High
171
Medium
94
Low
8

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
20
2
Integer Overflow
16
3
XSS
10
4
Out-of-bounds Read
7
5
SQL Injection
6

Most Affected Products

1. Parallels Desktop189
2. Parallels Parallels Plesk Panel85
3. Parallels Parallels Desktop Macos49
4. Parallels Parallels Desktop26
5. Parallels Parallels Plesk Small Business Panel16

Recent Vulnerabilities

See more →
ZDI-CAN-29220
CVSS 7.8high

ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-554
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-556
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-CAN-28886
CVSS 7.8high

ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-555
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-CAN-28885
CVSS 7.8high

ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-18263
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-18262
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-13121
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-25-1015
unknown

Parallels Toolbox CleanDrive Link Following Local Privilege Escalation Vulnerability

Nov 25, 2025🔧 No Patch

Monitor Parallels in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.