Wireshark disclosed a CMS protocol dissector vulnerability, tracked as CVE-2026-76881, that could crash Wireshark or TShark when processing malformed CMS SignedData. The bug was caused by CMS MessageDigest verification passing a missing digest AlgorithmIdentifier into strcmp() without a null check, creating a deterministic null pointer dereference during packet dissection. An attacker could trigger the crash by injecting a malformed packet onto the network or by convincing a user to open a crafted packet capture file.
The issue affected Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17, and was fixed in 4.6.8 and 4.4.18. Wireshark said the remediation adds a guard so missing algorithms are marked as "[unable to verify]" instead of causing a crash, though the original report noted a remaining limitation involving shared last-algorithm state across nested or consecutive decodes. The flaw was reported by researchers from Aisle Research, O2Lab, and Texas A&M University, and Wireshark said no active exploits were known at disclosure time.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security notice wnpa-sec-2026-76 for the CMS protocol dissector crash, stating that versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17 were affected and that fixes were available in 4.6.8 and 4.4.18. The advisory credited Aisle Research and named the discoverers, while noting that no exploits were known.
Wireshark merged remediation changes titled "CMS: Check if Digest Algorithm is NULL," adding a null guard so missing algorithms are marked as "[unable to verify]" instead of causing a crash. The issue was then closed by John Thacker with commit 02dd1e7a.
AISLE Research reported a medium-severity null pointer dereference in Wireshark's CMS MessageDigest verification logic that could deterministically crash Wireshark or TShark when dissecting a malformed SignedData structure. The issue was tracked in Wireshark as issue 21446 and later assigned CVE-2026-76881.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.