Wireshark disclosed CVE-2026-15164, a vulnerability in the ciscodump external capture interface that can cause the tool to crash when a user connects to a hostile device. The issue was documented in Wireshark advisory wnpa-sec-2026-63 and tracked in the project's GitLab issue tracker, with discovery credited to 0sec and Doruk Tan Ozturk.
The flaw affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Wireshark said the problem has been fixed in versions 4.6.7 and 4.4.17, and organizations using ciscodump should upgrade to those releases to prevent crashes that could be triggered through interaction with untrusted network devices.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
On July 8, 2026, Wireshark published security advisory WNPA-SEC-2026-63 for a crash vulnerability in the ciscodump external capture interface, tracked as CVE-2026-15164. The advisory says affected versions include 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and that exploitation would require convincing a user to connect to a hostile device.
Wireshark stated that the ciscodump extcap crash vulnerability was fixed in versions 4.6.7 and 4.4.17. The project recommended users upgrade to those releases or later.
Wireshark tracked a crash vulnerability in the ciscodump external capture interface under issue 21375. The issue is the bug tracker reference later cited by the security advisory for CVE-2026-15164.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.