JFrog disclosed CVE-2026-90894, a Parallels Desktop flaw on Apple ARM Macs that lets any local user escalate to root via argument injection in appliance extraction. Fixed in v27.0.0. #ParaShells #ParallelsDesktop #Alludo
Explore
Any local Mac user can root the box: Parallels trusts peer creds, a quoted folder name does the rest. https://intel.threadlinqs.com/threat/TL-2026-2536 #ThreatIntel #CVE_2026_90894 #tar #ParaShells
