Noowanjay Seeballack
Staff member
Parallels Client (Linux)
Parallels Client (Linux) (17 August 2026)
IGEL v21.2.1.1-27310
Parallels RAS Core v21.2.1.1-27310 (7 August 2026)
RAS REST API v21.2.1.1-27310 (7 August 2026)
RAS PowerShell v21.2.1.1-27310 (7 August 2026)
User Portal (Web client) (7 August 2026)
Parallels Client (Windows) v21.2.1.1-27311 (7 August 2026)
Parallels RAS Core v21.2.1-27306 (30 July 2026)
User Portal (Web client) (30 July 2026)
Parallels Client (Windows) v21.2.1-27302 (30 July 2026)
Parallels Client (Linux) v21.2.1-27300 (30 July 2026)
Parallels Client (Mac) v21.2.1-27300 (30 July 2026)
Reporting v21.2.1-27300 (30 July 2026)
Parallels Client (Windows) v21.2.0.1-27186 (8 July 2026)
Parallels Client (iOS) v21.2-27172 (7 July 2026)
Parallels Client (Android) v21.2-27172 (7 July 2026)
Parallels RAS Core v21.2-27178 (23 June 2026)
RAS REST API v21.2-27178 (23 June 2026)
RAS PowerShell v21.2-27178 (23 June 2026)
Management Portal (23 June 2026)
User Portal (Web client) (23 June 2026)
Parallels Client (Windows) v21.2-27179 (26 June 2026)
Parallels Client (Mac) v21.2-27169 (23 June 2026))
Parallels Client (Linux) v21.2-27178 (23 June 2026)
Parallels Client (iOS) v21.2-27167 (23 June 2026)
Parallels Client (Android) v21.2-27168 (23 June 2026)
Reporting v21.2-27178 (23 June 2026)
RAS Performance Monitor v21.2-27178 (23 June 2026)
HALB v21.2-27178 (23 June 2026)
RAS Performance Monitor v21.1.1.2-26699 (26 May 2026)
Parallels RAS Core v21.1.1.1-26691 (22 April 2026)
RAS REST API v21.1.1-26688 (9 April 2026)
RAS PowerShell v21.1.1-26688 (9 April 2026)
Management Portal (9 April 2026)
User Portal (Web client) (9 April 2026)
Parallels Client (Windows) v21.1.1-26688 (9 April 2026)
Parallels Client (Mac) v21.1.1-26688 (9 April 2026)
Reporting v21.1.1-26688 (9 April 2026)
Parallels RAS Core v21.1.0.1-26548 (25 March 2026)
Parallels Client (Windows) v21.1.0.1-26548 (25 March 2026)
User Portal (Web client) (25 March 2026)
Prior to March 2026 release information for Parallels RAS 21 is available here.
Parallels Remote Application Server v20 Release Notes can be found in the following article
For any assistance or direct support inquiries, please reach out to our support team by visiting Support | Parallels RAS
Parallels Client (Linux) (17 August 2026)
IGEL v21.2.1.1-27310
- Critical Fix: Sessions may reconnect unexpectedly every 10 seconds due to false desktop resize signals.
Parallels RAS Core v21.2.1.1-27310 (7 August 2026)
- Critical Fix: The VDI Provider Agent may stop responding when managing Hyper-V clusters, causing providers to appear as "Not verified" in the RAS Console. This occurred due to a conflict during guest state notifications that required a service restart to resolve.
- Improved: Add a registry setting to disable application monitoring on VDI Guest Agents. This prevents high memory consumption and performance degradation in the RAS Connection Broker during periods of high user activity or large-scale VDI deployments. New Registry key: AppMonitor. Please check KB 131171 for more details.
- Improved: Support runtime input locale propagation to ensure keyboard language changes are correctly redirected. To enable, the following registry key needs to be enabled on the host where the session is established: HKLM\Software\Wow6432Node\Parallels\MemShell ValueName: RedirectInputLocale Type: DWORD Value: 1.
RAS REST API v21.2.1.1-27310 (7 August 2026)
- Fixed: Creating or recreating RD Session Hosts fails.
RAS PowerShell v21.2.1.1-27310 (7 August 2026)
- Fixed: Creating or recreating RD Session Hosts using the Invoke-RASHostPool command fails.
User Portal (Web client) (7 August 2026)
- Fixed: The folder selection dialog for drive redirection does not appear for sessions initiated via the Connection Broker API, preventing users from configuring local folder access.
- Improved: Support runtime input locale propagation to ensure keyboard language changes are correctly redirected. To enable, the following registry key needs to be enabled on the host where the session is established: HKLM\Software\Wow6432Node\Parallels\MemShell ValueName: RedirectInputLocale Type: DWORD Value: 1.
Parallels Client (Windows) v21.2.1.1-27311 (7 August 2026)
- Improved: Support runtime input locale propagation to ensure keyboard language changes are correctly redirected. To enable, the following registry key needs to be enabled on the host where the session is established: HKLM\Software\Wow6432Node\Parallels\MemShell ValueName: RedirectInputLocale Type: DWORD Value: 1.
Parallels RAS Core v21.2.1-27306 (30 July 2026)
- New: Expose document printing preferences, including printer tray selections, made in remote sessions when printing via the RAS Universal Printer in User Portal sessions for third-party clients and extensions.
- Critical Fix: The Provider Agent may crash during Hyper-V management or VDI cloning due to intermittent access errors, connection resets, or while clearing active guest sessions during a host shutdown.
- Fixed: Users may be incorrectly assigned multiple hosts within the same host pool when launching an application if no hosts are currently available in the buffer.
- Fixed: The Enrollment Server may generate an excessive number of certificates in Active Directory if the Certificate Authority is unavailable at startup and fails to clean up associated private keys.
- Fixed: RAS Universal Printing preferences may show generic or irrelevant tray names when a redirected printer lacks specific client-side preferences. The Paper Source, Paper Form, and Print Quality options now correctly match the local printer settings.
- Fixed: Deletion of Hyper-V Cluster hosts may fail sporadically, leaving orphaned virtual machines or disk resources in the hypervisor.
- Fixed: RAS Universal Printing fails when using Azure Virtual Desktop (AVD) resources.
- Fixed: Web Authentication may show an incorrect username or password error with newly issued certificates, though login succeeds after dismissing the prompt.
- Fixed: VDI host cloning in a Hyper-V Cluster may fail if the system attempts to place new hosts on nodes that are paused, isolated, or quarantined.
User Portal (Web client) (30 July 2026)
- Security Fix: Node.js upgraded to v24.18.1.
- Security Fix: Applied security updates, including fixes for Cross-Site Scripting (XSS) and hardened SAML authentication flow.
- New: Expose document printing preferences, including printer tray selections, made in remote sessions for third-party clients and extensions.
- Fixed: The Ctrl key state may not be maintained during repeated paste (Ctrl+V) operations when using PC Keyboard mode.
- Fixed: Clipboard synchronization fails when a published application is moved to a secondary display, requiring focus to be returned to the primary browser window to resume.
- Fixed: Opening a published desktop in multi-monitor mode while a published application is already active on a second display causes the application window to freeze.
- Fixed: Keyboard layout is incorrectly detected as English (UK) when the client machine is set to English (US).
Parallels Client (Windows) v21.2.1-27302 (30 July 2026)
- New: A self-extracting Headless Client installer for x64 and ARM64, which enables streamlined deployments with minimal UI, restricted connection management, and no desktop or Start Menu icons.
- New: Ability to disable automatic connection refreshing when launching applications from the User Portal or shortcut items. This prevents redundant authentication prompts and pop-ups.
- New: Support for loading trusted root certificates directly from the Windows Certificate Store. This improves certificate validation performance and ensures compatibility with enterprise-managed certificates while maintaining a fallback to local PEM files. Please check KB131169 for more details.
- Improved: Updated trusted.pem root certificates (used if the Windows Certificate Store is inaccessible).
- Critical Fix: Published applications and desktops may fail to launch when using Gateway SSL mode if the "Server Authentication" setting is set to "Warn".
- Fixed: The secondary connection interface sets port 80 as the default instead of port 443 when SSL connection modes are selected.
- Fixed: Newly added local printers are incorrectly quarantined and fail to redirect to the remote session.
Parallels Client (Linux) v21.2.1-27300 (30 July 2026)
- Critical Fix: A crash may occur when attempting to connect and authenticate to a farm with Client Public IP Detection enabled.
- Critical Fix: Saved passwords and proxy settings may become corrupted after modifying client options or updating managed settings.
Parallels Client (Mac) v21.2.1-27300 (30 July 2026)
- New: Granular control for drive and folder redirection, which allows users to set specific access levels (Read & Write, Read Only, or No Access) for each redirected folder.
- Fixed: A crash may occur on launch after updating from an App Store version to a notarized package version.
- Fixed: An already-redirected folder, or one of its subfolders, could be selected again for drive redirection, resulting in redundant configurations.
- Fixed: Formatted text (HTML) copied from local applications may fail to paste into remote applications due to incorrect clipboard data formatting.
Reporting v21.2.1-27300 (30 July 2026)
- Fixed: The default "Machines by Type" report is missing from the Custom Reports category after enabling custom reports in the RAS Console.
- Fixed: Reporting service may fail to initialize the environment and process data due to a race condition during reconnection to the Connection Broker.
- Fixed: Application activity reports may display an incorrect start date of 1/1/1970 for sessions outside the data retention period due to a database upgrade script failing to execute during the update to RAS Reporting v21.2.
Parallels Client (Windows) v21.2.0.1-27186 (8 July 2026)
- Security Fix: Improved security in service to deploy installer and hardened privileged file-handling to prevent unauthorized local access.
Parallels Client (iOS) v21.2-27172 (7 July 2026)
- Fixed: Application launch fails when using web authentication.
Parallels Client (Android) v21.2-27172 (7 July 2026)
- Fixed: Application launch fails when using web authentication.
Parallels RAS Core v21.2-27178 (23 June 2026)
- Security Fix: Upgraded OpenSSL to version 3.5.6 and FIPS to version 3.1.2 with FIPS 140-3 validation.
- Security Fix: Upgraded .NET to version 10.0.7.
- New: Add support for Nutanix Prism Central as a provider, enabling new integration with the latest Nutanix platform architecture and Nutanix-native Templates, ensuring long-term compatibility with upcoming Nutanix API lifecycle changes. This enhancement allows organizations to better support modern hybrid and cloud-based Nutanix deployments managed through Prism Central while benefiting from a more scalable, consistent, and future-ready integration experience.
- New: Introduce the Custom Provider Framework, enabling administrators to integrate any hypervisor or virtualization platform (e.g., Proxmox) for automated VM lifecycle management, template versioning, and host pool provisioning using custom scripts. Please check the Custom Provider Framework guide for more details.
- New: Introduce granular access control for RAS Secure Gateways, allowing administrators to independently manage access to standard RAS sessions, User Portal authentication pages, Web API, and Connection Broker API. This reduces unnecessary exposure and strengthens security in specialized deployment scenarios.
- New: Add support for Scale Computing HC3 version 9.6 and deprecate support for version 9.2.
- New: Add support for Trusted Launch VM security type for Azure and Azure Virtual Desktop (AVD) providers, enabling Secure Boot and virtual TPM (vTPM) for enhanced security and support for modern Windows workloads.
- New: Ability to override virtual machine sizing and specifications at the host pool level for Azure, Azure Virtual Desktop, AWS, and Nutanix providers.
- New: Ability to override the Active Directory Organizational Unit (OU) at the host pool level, allowing a single template to be used across different host pools where hosts are stored in different organizational units.
- New: Support for Azure Availability Zones for Azure and Azure Virtual Desktop (AVD) providers, enabling administrators to specify zone placement for session hosts to optimize performance and reduce network latency.
- New: Support for custom time ranges in the Cost Insights dashboard, providing more flexibility for historical cloud cost analysis.
- New: Ability to configure automatic client logout while remote sessions remain active. This allows administrators to enforce re-authentication at the launcher level without interrupting running user sessions.
- New: Streamline multi-file uploads by allowing administrators to suppress "Save As" prompts, configure automatic file conflict resolution (overwrite or auto-increment), and enable the transfer window to auto-close upon completion.
- New: Add visibility and management controls for quarantined printers, helping administrators and users more easily identify printers that have been automatically isolated due to stability or driver-related issues.
- New: Introduce experimental file-content caching for redirected drives to improve performance when saving files from a remote session using Parallels Client for Windows. This feature is disabled by default and can be enabled via the new Registry key: WriteCacheEnabled. Please check KB 131152 for more details.
- New: Ability to configure the handling of sessions in a "Down" state, including improved visibility for sessions incorrectly marked as disconnected or active. Session hosts with "Down" sessions can now be automatically cleaned up using RAS schedules, with notifications generated when such sessions are detected. The registry key used in previous versions (ExcludeWTSDown) for handling Down sessions is now obsolete.
- New: Ability to configure the port used to connect to the Cost Insights service.
- Improved: Updated keyboard mapping policies for macOS to allow granular mapping of left and right modifier keys (Control, Option, Command, and Shift), providing administrators with finer control over how local keys are redirected to remote Windows sessions, with better compatibility for language-specific toggles.
- Improved: Add an informative message to clarify that application packages cannot be verified outside of an active user session.
- Improved: Add support for additional VDI cloning error codes to provide clearer status information in the RAS Console.
- Improved: Add validation to prevent the use of unsupported wildcard characters in URL redirection rules.
- Improved: Improve URL validation for custom "Change domain password" links to reject malformed formats.
- Improved: Rename the "Smart cards" redirection option to "Smart cards or Windows Hello for Business" in policies to align with Microsoft terminology.
- Improved: Ability to configure custom thresholds for failed Secure Gateway tunneled session notifications, allowing administrators to receive alerts only when failures exceed a specific threshold.
- Improved: Ensure consistent server address validation in all provider and agent property dialogs.
- Improved: Update the Document Publishing Wizard to use consistent terminology when publishing files instead of applications.
- Improved: Improve performance when loading the VDI Hosts tab in environments with a large number of guest VMs.
- Improved: SAML login performance and Enrollment Server stability by optimizing certificate handling and installation processes, significantly reducing delays when the user profile contains a large number of certificates.
- Improved: Add "uxevaltime" parameter to the Connection Broker API to configure the UX Evaluator counter.
- Improved: Specify a custom HTTP request header (e.g., X-Real-IP) to override the default "X-Forwarded-For" using the "RealIPHttpHeader" registry key for accurate client IP reporting through load balancers. Please check KB 131154 for more details.
- Improved: Support for sorting and grouping by events in the Notifications section.
- Improved: The RAS Watchdog service now monitors the Enrollment Server service to ensure high availability.
- Improved: Prevent the Enrollment Server from creating multiple certificates for the same user during simultaneous logon requests.
- Improved: Set the default connection mode for secondary connections to Gateway SSL in policies.
- Improved: Add certificate usage types for Connection Broker API Server and Data Encryption in the certificate management sections.
- Improved: Update the predefined list of Windows Client and Windows Server images with the latest SKUs available in the Azure Gallery for Azure Virtual Desktop (AVD) template creation.
- Improved: Enhanced error handling and reporting in Cost Insights for database connectivity issues, missing Azure credentials, and incorrect authentication states.
- Improved: Stability and performance of drag-and-drop operations by optimizing data handling and reducing redundant server-to-client requests.
- Improved: Add CNG API support for certificate key management, enabling modern Key Storage Providers (KSP) and ensuring compatibility with Windows security updates.
- Improved: Stability and robustness of the Connection Broker when processing multiple management commands or recreating RD Session Hosts in parallel.
- Improved: Increase visibility into the provisioning process with a new "Queued" status for clones that have been accepted but not yet started.
- Improved: Simplify the Guest Agent discovery process by removing legacy broadcasting mechanisms.
- Improved: Virtual machines already assigned to a standalone host pool or used as a template source are now filtered out from the selection list when adding new members or creating templates.
- Improved: Settings Audit filtering now supports 12-hour/24-hour formats with meridiem indicators, and local console timezones for more accurate log searches.
- Improved: Joining a Site to a Tenant Broker provides clearer error messages and detailed logging when an invitation hash is invalid or mismatched.
- Critical Fix: Potential RAS Console crash when deleting a large number of devices simultaneously.
- Critical Fix:: Potential RAS Console crash when selecting a large number of sessions to view resource details.
- Fixed: Incorrect suggestion to recreate a template when entering maintenance mode for VDI templates with distribution enabled was being shown.
- Fixed: Verbose logging and log retrieval may fail for Secure Gateways located in secondary sites.
- Fixed: RAS Console becomes temporarily unresponsive after applying configuration changes in environments with large databases.
- Fixed: Applications may fail to browse network folders with short names (4 characters or less) when Drive Redirection Cache is enabled.
- Fixed: The Template tab is incorrectly displayed for RD Session Host pools configured as standalone.
- Fixed: Unsupported provider versions incorrectly remain in a "Synchronizing" state instead of showing "Unsupported".
- Fixed: RD Session Host clones are not correctly deleted if a deletion request is made while cloning is still in progress.
- Fixed: HALB Virtual Servers view incorrectly displays IP addresses that do not match the selected IP version.
- Fixed: The Knowledge Base link on the Client Public IP detection page incorrectly points to private IP documentation.
- Fixed: RAS Console reports incorrect client OS information when switching between different RDP clients using the same user account.
- Fixed: Duplicate entries for the same Azure Virtual Desktop (AVD) Workspace may appear in the RAS Console after a failed creation attempt.
- Fixed: Azure VDI template disks may remain as orphaned resources in Microsoft Azure when repeatedly switching between template versions in maintenance mode.
- Fixed: Azure Virtual Desktop (AVD) disk storage cost optimization data is not sent to the reporting database immediately after the feature is enabled.
- Fixed: Canceling the workspace creation wizard after adding an Azure Virtual Desktop (AVD) provider may result in duplicate provider records.
- Fixed: A persistent error message logs every five minutes when a template deleted directly from the provider remains in the RAS database.
- Fixed: Azure Virtual Desktop (AVD) autoscaling may create more hosts than the configured maximum limit due to a race condition during provider reconnection.
- Fixed: Scanning policy settings for WIA and TWAIN redirected scanners do not update correctly in the UI when switching between scanning technologies.
- Fixed: Host pools using a Hyper-V Cluster template are incorrectly recreated when leaving maintenance mode, even if the administrator chooses not to recreate the hosts.
- Fixed: VMware ESXi or vCenter providers fail to connect or report "InvalidCredentials" when using a non-standard HTTPS port.
- Fixed: Enrollment Server could create duplicate certificates for the same user when multiple concurrent logon requests required a new user certificate, which could cause the user logon request to fail.
- Fixed: Deleting a host pool may fail to remove hosts created from Hyper-V replicas on non-primary providers when Hyper-V template distribution is enabled.
- Fixed: Applying settings in the RAS Console triggers unnecessary provider synchronization even when no provider-related changes were made. This optimization prevents lengthy host syncing operations that could temporarily block communication between the Connection Broker and the Provider Agent in large environments.
- Fixed: The directory count limit for drive redirection cache is applied incorrectly, resulting in a lower limit than the value specified in the DirCountLimit registry key.
- Fixed: Deleted files or folders may still appear in the file list when using drive redirection with caching enabled.
- Fixed: Applications may fail to open or process files in redirected folders due to missing file metadata.
- Fixed: Settings Audit filtering does not return results when searching for the "Delete" action.
- Fixed: Duplicate records appear in the Secure Gateway security settings when toggling "Inherit default settings".
- Fixed: RAS Console may crash when a custom administrator with specific permissions attempts to access the Sessions > Resources tab.
- Fixed: Application packages remain on standalone VDI hosts or RD Session Hosts after the host is removed from a host pool.
- Fixed: Tenant Broker Gateway incorrectly routes authentication requests to standby Connection Brokers during load balancing.
- Fixed: The Provider Agent may crash when adding a Hyper-V provider due to an error when processing host performance data.
RAS REST API v21.2-27178 (23 June 2026)
- Security Fix: Upgraded .NET to version 10.0.7.
- New: Introduce API version 5 and drop version 3.
- New: Introduce an administrative API endpoint (/api/PubEffectiveAccess) to retrieve a list of published resources available to specific users without requiring end-user authentication.
- Improved: The GET /api/VDI/HostPool/{id}/Members endpoint now returns an empty array instead of an error when querying a VDI host pool that has no members.
- Improved: Expose disk type information for Application Packages.
- Fixed: Importing a certificate with an incorrect password causes the RAS Web Admin Service to fail on restart. The service now validates the certificate password before applying changes.
- Fixed: The GET /api/WinDeviceGroup endpoint fails to return results when filtering by SiteId together with Name.
- Fixed: Retrieving the process list for a specific RD Session Host session fails with an exception.
RAS PowerShell v21.2-27178 (23 June 2026)
- Security Fix: Upgraded .NET to version 10.0.7.
- New: Introduce API version 5 and drop version 3.
- New: Add the Get-RASPubEffectiveAccess command to retrieve the list of published resources available to specific users without requiring end-user authentication.
- Improved: The Get-RASVDIHostPoolMember command now returns an empty array instead of an error when querying a VDI host pool that has no members.
- Improved: Expose disk type information for Application Packages.
- Fixed: The Get-RASWinDeviceGroup command fails when using the -SiteID parameter together with -Name.
Management Portal (23 June 2026)
- Security Fix: Upgraded .NET to version 10.0.7.
- New: Add configuration settings to manage sessions in a "down" state, including visibility in the sessions page and automated host drain actions.
- Fixed: Importing a certificate with an incorrect password via "Configure Management Portal" causes the RAS Web Admin Service to fail on restart. The service now validates the certificate password before applying changes.
- Fixed: Uploading an SSL certificate in the management portal configuration fails to provide validation or apply the changes.
- Fixed: "Insufficient permissions" error when custom administrators attempt to manage user sessions.
- Fixed: "Index out of range" error when navigating the Sessions tab.
- Fixed: Search in Secure Gateways and Sessions view does not filter results as expected.
- Fixed: Issues in configuring RADIUS automation conditions, including incorrect default pattern names and UI synchronization errors when adding consecutive conditions or saving and canceling changes.
User Portal (Web client) (23 June 2026)
- Security Fix: Upgrade Node.js to v24.17.0.
- Security Fix: Add size limits to SAML decompression to mitigate potential denial-of-service (DoS) attacks from decompression bombs.
- New: Add drive redirection support on Chromium-based browsers, allowing users to access local folders and files within published applications and desktops.
- New: Introduce a secure authentication handoff API that enables organizations to transfer authentication context between external systems and the RAS User Portal. This allows auto login and/or launching remote sessions directly via the RAS Web Client with enhanced security. It replaces the deprecated legacy web client launcher API. Please note that the old API is disabled by default, find more information and migration details here KB 131148.
- New: Add support for macOS modifier key mapping when accessing the User Portal from macOS devices. This allows users to configure how the Command (⌘), Control, Option, and Shift keys are redirected to the remote session, enabling the use of native macOS shortcuts (e.g., ⌘+C, ⌘+V) and improving productivity.
- New: Support for automatic logout after a period of inactivity, even when remote sessions are still running in other tabs.
- New: Add support for multi-file uploads via drag-and-drop or multi-file selection, immediately starting transfers when a default path is configured to eliminate repetitive "Save As" prompts and automatically closing the transfer window upon completion.
- New: Automatic detection of local keyboard layout to set as the default PC keyboard layout for remote sessions.
- New: Add support for launching published resources using Web + Credentials authentication via the Parallels Client for Windows.
- Improved: Show the user's Display Name in the user profile menu.
- Improved: Enhance the User Portal settings modal on mobile devices to improve navigation and usability.
- Fixed: Printing multiple documents from Google Chrome may fail after the first document.
- Fixed: The file download dialog appears behind active windows during a published desktop session.
- Fixed: Users are required to log in again after a successful password change when the "User must change password at next logon" option is enforced in Active Directory.
- Fixed: Launching a published application via the Parallels Client fails when an "undefined" theme name is incorrectly passed in the connection details.
- Fixed: Application windows may become unresponsive and remain stuck with a drag-and-drop border if the browser loses focus during a file transfer attempt.
- Fixed: Command line parameters passed via Direct App Access URLs may be incorrectly decoded, causing arguments containing special characters (like "+") to be split or misinterpreted by the published application.
- Fixed: Published resource icons may fail to appear in the User Portal after switching between standard and high-definition icon resolutions.
- Fixed: The loading spinner and application icon may be incorrectly aligned and sized when starting a published application.
- Fixed: User Portal Server logs may continue to be written to the backup log file instead of a newly created log file after a manual rename or rotation.
- Fixed: Web authentication logout fails with a "missing SSO" error when using the internal browser in the Parallels Client for Windows.
- Fixed: Modifier keys (such as Shift and Ctrl) are intermittently ignored during mouse clicks, preventing actions like range or multi-selection in published applications.
- Fixed: Browser tabs remain open after a published application launched in a new tab is closed.
- Fixed: Sign out fails with an error after launching a published resource when using "Web + Credentials" authentication.
- Fixed: Users with non-Latin characters in their usernames are unable to log in.
Parallels Client (Windows) v21.2-27179 (26 June 2026)
- Security Fix: Address local privilege escalation vulnerabilities by enforcing digital signature verification of the installers and the calling process.
- Security Fix: Upgraded OpenSSL to version 3.5.6 and FIPS to version 3.1.2 with FIPS 140-3 validation.
- Security Fix: Upgraded .NET to version 10.0.7.
- New: Allow users to access the password reset functionality even without an active connection to the farm by retaining the last used external password change URL.
- New: Support for automatic logout after a period of inactivity, even when remote sessions are still running.
- New: Add visibility and management controls for quarantined printers, helping users identify and restore printers that were automatically isolated due to stability or driver-related issues.
- New: Introduce experimental file-content caching for redirected drives to improve performance when saving files from a remote session. This feature is disabled by default and can be enabled via the new Registry key: WriteCacheEnabled. Please check KB 131152 for more details.
- New: Add support for launching published resources using Web + Credentials authentication when initiated from the User Portal.
- Improved: Update password expiration alerts to provide clearer, more concise notifications.
- Improved: Rename the "Smart cards" redirection option to "Smart cards or Windows Hello for Business" to align with Microsoft terminology.
- Improved: The connection banner now remains visible for a longer duration during the application launch process, reducing user confusion and preventing multiple accidental launches of the same resource.
- Improved: Set the default connection mode for secondary connections to Gateway SSL.
- Improved: Update system tray icon design for a consistent user experience.
- Improved: Increase readability of the modern UI launcher by adjusting background transparency to align with standard Windows application behavior.
- Fixed: The context menu for published local applications incorrectly displays RAS Connection options instead of application-specific actions in the classic UI.
- Fixed: Both Parallels Client Modern and Classic UI may launch simultaneously on first install if the Modern UI takes too long to initialize.
- Fixed: Shadowing a managed device fails in SSL Tunnel mode unless port 50005 is open.
- Fixed: The "Send OTP" button in the login dialog appears truncated after closing an error message.
- Fixed: The cursor during drag operations displays an outdated icon instead of the new or branded application icon.
- Fixed: USB flash drives and local disks may fail to redirect during the first login session, especially in environments using Unified Write Filter (UWF). A race condition caused the client to reload default settings from the registry before fully applying the RAS policy. The synchronization logic has been improved to ensure policies persist and apply correctly.
- Fixed: Published application icons may fail to appear on a freshly installed client until a manual refresh is performed.
- Fixed: Local applications on secondary monitors may stop responding to mouse clicks after a RAS session reconnection in RemoteApp mode.
- Fixed: The Windows Client installer incorrectly prompts that unrelated applications are in use during the upgrade process.
- Fixed: A warning appears when closing a RemoteApp published application if the user authenticates via SAML.
- Fixed: Incorrect light theme icons are displayed in the Modern UI launcher when the system appearance is set to dark mode.
- Fixed: Drag and drop functionality from a remote server to the local client may fail if the temporary directory path is not immediately accessible during session initialization.
- Fixed: The connections list and status bar do not automatically refresh when adding a new connection via the CLI.
- Fixed: The credentials prompt is incorrectly pre-populated with the local user instead of the SAML-authenticated user during the first login when using Web + Credentials authentication.
- Fixed: An extra login dialog with an empty, read-only username field appears when launching resources in environments using "Web + Credentials" authentication with the "Prohibit saving username" policy enabled.
- Fixed: Printer preference dialogs disappear and cause the client to hang when minimizing and restoring a published application with Z-Order enabled.
- Fixed: Window focus changes unexpectedly when opening local printer properties when Z-Order is enabled.
- Fixed: Connections fail when using a SOCKS5 proxy that requires authentication.
Parallels Client (Mac) v21.2-27169 (23 June 2026))
- Security Fix: Upgraded OpenSSL to version 3.5.6 and FIPS to version 3.1.2 with FIPS 140-3 validation.
- New: Add support for "Web + Credentials" authentication mode, enabling organizations to combine modern SAML-based authentication with traditional Active Directory session logins.
- New: Add support for bidirectional clipboard redirection of images between the local Mac and remote applications.
- New: Allow users to access the password reset functionality even without an active connection to the farm by retaining the last used external password change URL.
- New: Support for automatic logout after a period of inactivity, even when remote sessions are still running.
- Improved: Enhance support for international keyboard layouts by allowing granular mapping of left and right modifier keys (Control, Option, Command, and Shift). This enables better compatibility for language-specific toggles, such as the Hangul/English switch in Korean layouts, and improves access to special characters in various European layouts.
- Improved: Update the printer driver list by removing obsolete Windows Server 2003 and 2008 options and streamlining the "MS Publisher Color Printer" selection.
- Improved: Rename the "Open PDF in Preview" option to "Enable opening PDF in macOS Preview" to more accurately describe its functionality.
- Improved: Modernize the UI to comply with the OS 26 design framework.
- Improved: Update password expiration alerts to provide clearer, more concise notifications.
- Fixed: Keyboard shortcut mapping headers are misaligned when using the client in non-English languages.
- Fixed: Pressing Windows Key + L within a published application incorrectly locks the remote session.
- Fixed: The mouse cursor may intermittently reset to the default macOS arrow instead of the redirected Windows cursor.
- Fixed: Hardware ID filtering fails for Mac devices connected via VPN because the client does not pass the physical network adapter's MAC address.
- Fixed: Error dialog for external disk root in drive redirection could become stuck and not dismissible.
- Fixed: Redundant error messages appear when a published application launch is canceled or fails due to network issues.
- Fixed: Policy details are not displayed in the connection properties when only "Control Setting" is configured in a policy.
Parallels Client (Linux) v21.2-27178 (23 June 2026)
- Security Fix: Upgraded OpenSSL to version 3.5.6 and FIPS to version 3.1.2 with FIPS 140-3 validation.
- New: Add support for "Web + Credentials" authentication mode, enabling organizations to combine modern SAML-based authentication with traditional Active Directory session logins.
- New: Allow users to access the password reset functionality even without an active connection to the farm by retaining the last used external password change URL.
- New: Support for automatic logout after a period of inactivity, even when remote sessions are still running.
- New: Extended USB redirection support to allow additional device classes, such as HID-compliant signature pads and scanners.
- New: Add support for Fedora 44.
- Critical Fix: Subsequent users on shared thin clients encounter continuous SAML authentication loops when launching published resources.
- Fixed: The client fails to launch in restricted network environments where a default gateway is present, but internet access is unavailable.
- Fixed: The client process may continue running in the background after the main window is closed on systems without a system tray.
- Fixed: Users are repeatedly prompted for credentials when establishing an RDP connection, even if "save password" is enabled.
- Fixed: Saved passwords for RDP connections are not correctly applied, resulting in redundant credential prompts.
- Fixed: The idle session timeout is not correctly reset after closing the "Change Password" window.
- Fixed: Local printers are incorrectly redirected to the remote session even when the printing technology is set to "None" in the connection properties.
Parallels Client (iOS) v21.2-27167 (23 June 2026)
- Security Fix: Upgraded OpenSSL to version 3.5.6.
- New: Add support for "Web + Credentials" authentication mode, enabling organizations to combine modern SAML-based authentication with traditional Active Directory session logins.
- New: Allow users to access the password reset functionality even without an active connection to the farm by retaining the last used external password change URL.
- Improved: Include device vendor and model information when establishing standard RDP connections to improve device identification and management.
- Improved: Modernize the UI to comply with the OS 26 design framework.
- Improved: Update password expiration alerts to provide clearer, more concise notifications.
- Critical Fix: The application may crash during web authentication when an invalid URL is processed while attempting to establish a connection.
- Fixed: Audio recording remains enabled in settings when sound redirection is set to "Leave at remote computer."
- Fixed: Published applications may fail to launch on the first attempt when multiple sessions, such as a published desktop and a published application, are running simultaneously.
- Fixed: Front camera image appears upside down during webcam redirection on iPad models with a landscape-oriented camera.
- Fixed: Background audio and dictation software stop working when the Parallels Client is in the foreground. The audio session now initializes only when actively streaming or recording, preventing the client from unnecessarily capturing system audio focus.
Parallels Client (Android) v21.2-27168 (23 June 2026)
- Security Fix: Upgraded OpenSSL to version 3.5.6.
- New: Add support for "Web + Credentials" authentication mode, enabling organizations to combine modern SAML-based authentication with traditional Active Directory session logins.
- New: Allow users to access the password reset functionality even without an active connection to the farm by retaining the last used external password change URL.
- Improved: Include device vendor and model information when establishing standard RDP connections to improve device identification and management.
- Improved: Update password expiration alerts to provide clearer, more concise notifications.
- Critical Fix: The client may crash during reconnection attempts when the network connection to the farm is lost.
- Fixed: Published applications may fail to launch on the first attempt when multiple sessions, such as a published desktop and a published application, are running simultaneously.
- Fixed: Unable to import connection settings from .2xc files on devices running Android 14 and later.
Reporting v21.2-27178 (23 June 2026)
- Fixed: Application activity reports may display an incorrect start date of 1/1/1970 when the actual start time is outside the data retention period.
- Fixed: Sessions across different servers in an Azure Virtual Desktop (AVD) host pool are incorrectly displayed with the same host name in the "Sessions activity for AVD Host Pool" report.
- Fixed: Reports cannot be exported to disk from the RAS Console.
RAS Performance Monitor v21.2-27178 (23 June 2026)
- Security Fix: Upgraded Telegraf to version 1.36.4.
- Security Fix: Address an unquoted service path vulnerability in the service management configuration to prevent potential local privilege escalation.
- Fixed: The installer fails to automatically detect custom Grafana ports configured in custom.ini or environment variables, resulting in empty dashboards after installation.
HALB v21.2-27178 (23 June 2026)
- Security Fix: Upgraded OpenSSL to version 3.5.6 and FIPS to version 3.1.2 with FIPS 140-3 validation.
- New: Include network diagnostics tools such as ping, traceroute, and curl within the HALB container for easier troubleshooting via SSH.
- New: Ability to ping an IP address directly from the Advanced > Networking menu in the HALB appliance console.
- New: Support for copying files to and from the HALB appliance using SFTP and SCP.
- Improved: Optimize disk space usage by rotating and compressing HALB logs based on file size rather than time.
- Improved: Reduce the HALB appliance image size for Hyper-V by using thin provisioning.
- Fixed: The VRRP broadcast interval is incorrectly applied in seconds instead of minutes, causing gratuitous ARPs to be sent more frequently than configured.
- Fixed: The VRRP health script timeout setting configured in the RAS Console is not correctly applied to the HALB appliance.
- Fixed: Unable to manually configure a static IPv6 address in the HALB appliance network configuration interface.
- Fixed: HALB appliances are unreachable or fail to communicate with devices when assigned an IP address in the 172.17.0.0/16 range due to an internal network conflict.
RAS Performance Monitor v21.1.1.2-26699 (26 May 2026)
- Improved: The Parallels RAS Performance Monitor installer now automatically detects local Grafana installations, required as a prerequisite, to deploy dashboards and configure performance metrics. This enables independent management of Grafana installations, allowing organizations to select their preferred Grafana edition and update versions on their schedule. More information in KB124973.
Parallels RAS Core v21.1.1.1-26691 (22 April 2026)
- Security fix: Enhanced security hardening during the web authentication flow.
- New: Add support for customer-defined Secure Ticket Authority (STA) in the Connection Broker API, enabling third parties to use their internal STA for authentication.
- Improved: Add registry-configurable options to the RAS Watchdog service, enabling administrators to automatically monitor and restart RAS services if they are stopped unexpectedly by external factors. New registry keys: InitialTimeToWait, KeepMonitoring, QuarantineTime, and TimeInterval allow fine-tuning of monitoring and quarantine behavior. Please check KB131113 for instructions.
- Fixed: Published applications may lose keyboard input after switching focus between local and remote windows. Update activation logic to skip deactivation if an activation is received before the delayed deactivation timer expires. This can be enabled via a new registry option: ActivationMode. This can be enabled via a new registry option: ActivationMode. Please check KB131112 for instructions.
RAS REST API v21.1.1-26688 (9 April 2026)
- Fixed: Adding a powered-off or disconnected agent using the create Broker endpoint triggered an unknown exception.
RAS PowerShell v21.1.1-26688 (9 April 2026)
- Security Fix: PowerShell data files and PowerShell XML formatting and type files were unsigned.
- Fixed: Adding a powered-off or disconnected agent using New-RASBroker command triggered an unknown exception.
Management Portal (9 April 2026)
- Fixed: Adding a powered-off or disconnected agent in the RAS Management Portal triggered an unknown exception.
User Portal (Web client) (9 April 2026)
- Security Fix: Encrypt data sent between the RAS Secure Gateway and Connection Broker when logging in via the User Portal.
- Security Fix: Address Cross-Site WebSocket Hijacking (CSWSH) vulnerability by enforcing strict origin checks on WebSocket connections, preventing unauthorized access from malicious sites.
- Security Fix: Harden Content Security Policy (CSP) headers and enforce trusted types in scripts.
- Security Fix: Upgrade Node.js to the latest March 2026 security release (v20.20.2).
Parallels Client (Windows) v21.1.1-26688 (9 April 2026)
- Security Fix: Validate the gateway certificate's Subject Alternative Name (SAN) when establishing connections, ensuring connections are only considered secure if the hostname matches the certificate, and preventing potential man-in-the-middle attacks.
- Critical Fix: The user workstation may hang when using RemoteApp due to a race condition.
- Improved: Add port length validation to the ALB Port field.
Parallels Client (Mac) v21.1.1-26688 (9 April 2026)
- Security Fix: Validate the gateway certificate's Subject Alternative Name (SAN) when establishing connections, ensuring connections are only considered secure if the hostname matches the certificate, and preventing potential man-in-the-middle attacks.
- New: Add the ability to open the folder redirection dialog automatically when accessing an empty redirected drive for the first time, improving user experience with drive redirection configuration.
Reporting v21.1.1-26688 (9 April 2026)
- Fixed: Upgrading RAS Reporting fails on SQL Server 2016 due to unsupported SQL commands in upgrade scripts.
- Fixed: Upgrading RAS Reporting from v20.2 to v21.0 could fail due to missing execution of patch scripts at the start of installation.
Parallels RAS Core v21.1.0.1-26548 (25 March 2026)
- Improved: Provider Agents no longer reload and reapply settings after every configuration change when the change is unrelated to that specific provider.
Parallels Client (Windows) v21.1.0.1-26548 (25 March 2026)
- New: Add ALB server and port settings to Web authentication. These settings can be used when the Load Balancer uses different entry points for ALB and NLB requests, allowing the same IdP configuration to be shared between User Portal and Parallels Client for Windows.
User Portal (Web client) (25 March 2026)
- Fixed: External monitoring checks against the User Portal URL could intermittently time out when the monitoring service reused the same TCP connection.
Prior to March 2026 release information for Parallels RAS 21 is available here.
Parallels Remote Application Server v20 Release Notes can be found in the following article
For any assistance or direct support inquiries, please reach out to our support team by visiting Support | Parallels RAS
Last edited: