SecAlerts
P

Parallels

Security Risk Profile

55
/100
medium

Security Risk Score

Comprehensive risk assessment based on 302 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 8, 2006 to present

302
Total CVEs
194
Critical+High
3
Exploited
191
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
191
Critical/High
Risk Level
55/100
medium
⚠️ 3 Active Exploits⚡ 1 Zero-Days🆕 108Fresh (<7d)📈 109 in Last 30 Days

Severity Distribution

Critical
22
High
172
Medium
94
Low
8

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
20
2
Integer Overflow
16
3
XSS
10
4
Out-of-bounds Read
7
5
SQL Injection
6

Most Affected Products

1. Parallels Desktop189
2. Parallels Parallels Plesk Panel85
3. Parallels Parallels Desktop Macos49
4. Parallels Parallels Desktop27
5. Parallels Parallels Plesk Small Business Panel16

Recent Vulnerabilities

See more →
CVE-2026-90894
CVSS 7.8EPSS 0%high

Parallels Desktop local privilege escalation via appliance extract argument injection

Sep 14, 2026🔧 No Patch
ZDI-CAN-29220
CVSS 7.8high

ZDI-26-554: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-554
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-556
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-CAN-28886
CVSS 7.8high

ZDI-26-556: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-26-555
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
ZDI-CAN-28885
CVSS 7.8high

ZDI-26-555: Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-18263
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-18262
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch
CVE-2026-13121
CVSS 7.8high

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability

Aug 11, 2026🔧 No Patch

Monitor Parallels in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.