Wireshark disclosed and patched multiple vulnerabilities in its Catapult DCT2000 handling code, including a protocol dissector crash tracked as CVE-2026-15174 and a separate file parser flaw later assigned CVE-2026-76883. The first issue, published as advisory wnpa-sec-2026-52, affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16 and can be triggered by a malformed packet on the wire or by opening a malformed packet trace file, causing the application to crash.
A later advisory, wnpa-sec-2026-74, covers a Catapult DCT2000 file parser crash affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17, fixed in 4.6.8 and 4.4.18. Separately, a GitLab issue detailed an off-by-one heap out-of-bounds write in parse_line() within wiretap/catapult_dct2000.c, where the parser allocates floor(data_chars/2) bytes but may write ceil(data_chars/2) bytes when the input length is odd; developers confirmed the bug, noted practical triggering requires exactly 2049 bytes, and merged fixes. Wireshark said no exploits are known for the disclosed issues and advised users to upgrade to patched releases.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
On August 12, 2026, Wireshark published security notice wnpa-sec-2026-74 for a Catapult DCT2000 file parser crash affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17. The notice credits Yazan Balawneh of the CyStack Security Team, references issue 21427, and says the flaw was fixed in versions 4.6.8 and 4.4.18.
A GitLab issue created on July 21, 2026 reported a distinct heap out-of-bounds write in Wireshark's Catapult DCT2000 wiretap file reader, caused by an off-by-one allocation bug in parse_line(). The report, submitted by Yazan Balawneh of the CyStack Security Team, noted the flaw was separate from wnpa-sec-2026-52 / CVE-2026-15174 and included a proof-of-concept malformed file.
On July 8, 2026, Wireshark disclosed security advisory wnpa-sec-2026-52 for a Catapult DCT2000 protocol dissector crash tracked as CVE-2026-15174. The issue affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and Wireshark said it was fixed in 4.6.7 and 4.4.17.
Wireshark developers confirmed and fixed the Catapult DCT2000 file reader bug through merged merge requests tied to issue 21427, and Gerald Combs later stated the vulnerability had been assigned CVE-2026-76883. The issue record says it was initially handled as a security issue before being made publicly visible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.