Wireshark released versions 4.6.9 and 4.4.19, addressing 19 documented security vulnerabilities and 16 additional bugs. The fixes span protocol dissectors, capture-file parsers, Sharkd, and configuration-profile handling, with many flaws triggered by malformed input capable of crashing the application, causing excessive or infinite loops, leaking memory, or creating denial-of-service conditions for analysts opening untrusted captures and related files.
The most significant issue, CVE-2026-96419 (wnpa-sec-2026-106), can be triggered by importing a crafted configuration profile and may crash Wireshark or potentially enable arbitrary code execution. Wireshark reported no known active exploitation, but organizations should promptly update deployments and avoid or isolate untrusted configuration profiles, packet captures, and other input files until patched.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark identified CVE-2026-96419 (wnpa-sec-2026-106), affecting versions 4.6.0–4.6.8 and 4.4.0–4.4.18. A crafted configuration profile could crash Wireshark or potentially execute arbitrary code when imported; Wireshark said it was unaware of active exploitation.
Wireshark released versions 4.6.9 and 4.4.19, addressing 19 documented vulnerabilities and 16 additional bugs. The fixes cover protocol dissectors, capture-file parsers, Sharkd, and configuration-profile handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalware.news
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.