Wireshark released version 4.6.8 with fixes for a large set of security vulnerabilities spanning packet dissectors, codecs, parsers, and related utilities. The advisory tracks issues under wnpa-sec-2026-08 through wnpa-sec-2026-50 and describes widespread crash conditions, infinite loops that can trigger denial of service, and several flaws marked as possible code execution, including issues in the TLS dissector, RDP dissector, SBC codec, and profile import functionality. Affected components also include handlers for protocols such as SMB2, HTTP, WebSocket, ZigBee, MySQL, ICMPv6, and OpenFlow, highlighting risk across Wireshark’s packet parsing and decompression surface.
Supporting issue reports show specific parser weaknesses such as a BT-DHT dissector stack overflow via nested structs and an FC-SWILS dissector stack overflow via nested zone set objects, while CVE tracking includes identifiers such as CVE-2026-5408 and CVE-2026-5409. The release notes also reference additional non-CVE defects involving memory corruption, integer underflow, heap overflow, parser overflows, and stability problems in Sharkd, underscoring that malformed capture data or imported content could crash analysis workflows and, in some cases, potentially lead to code execution.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry disclosed CVE-2026-76886, a heap-based buffer overflow / denial-of-service flaw in Wireshark's C12.22 protocol dissector affecting versions before 4.6.8 and 4.4.18. The record references Wireshark advisory wnpa-sec-2026-75 and GitLab work item 21439.
Wireshark published advisory wnpa-sec-2026-08 for CVE-2026-5409, a crash vulnerability in the Monero dissector affecting versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The issue could be triggered by a malformed packet or packet trace file and was fixed in versions 4.6.5 and 4.4.15.
A GitLab issue was opened to track an FC-SWILS dissector stack overflow via nested zone set objects, corresponding to CVE-2026-5406. The Wireshark advisory identified the issue as a crash-causing vulnerability.
A GitLab issue was opened to track a BT-DHT dissector stack overflow via nested structs, corresponding to CVE-2026-5408. The flaw was described in the Wireshark advisory as causing a crash.
Wireshark published release notes for version 4.6.8 that disclosed a large batch of vulnerabilities tracked as wnpa-sec-2026-08 through wnpa-sec-2026-50. The issues affected numerous dissectors, codecs, parsers, and utilities, including crashes, infinite loops, and several possible code execution flaws.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceheise.de
Open sourceisc.sans.edu
Open sourcewireshark.org
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.