Vulnerability
Published 2026-09-23
Verified 2026-09-28

Wireshark 4.6.9 / 4.4.19 (23 Sep): 19 advisories — profile-import possible code execution CVE-2026-96419 + dissector/parser crashes

Wireshark project security advisories wnpa-sec-2026-92 through wnpa-sec-2026-110 (dated 23 September 2026; Cybersecurity News amplified 28 Sep) fix nineteen issues in the 4.6 and 4.4 trains. Highest-impact: CVE-2026-96419 (wnpa-sec-2026-106) — importing a crafted configuration profile could crash Wireshark or execute arbitrary code (discovered by 경배 지; vendor unaware of exploits). Remaining eighteen are chiefly protocol-dissector or file-parser crashes / infinite loops / memory leaks from malformed packets or capture files (e.g. IEEE 802.11 CVE-2026-96416, X11 CVE-2026-96423, SCTP CVE-2026-95389, ZigBee ZCL CVE-2026-95391, USB HID CVE-2026-96421, Sharkd CVE-2026-95388, Catapult DCT2000 CVE-2026-96415). Fixed versions: 4.6.9 and (where listed) 4.4.19. No CVSS scores published on the wnpa-sec pages. Primary: Wireshark security advisories; wire: CSN 28 Sep.

Product
Wireshark (packet analyzer) / Stratoshark family dissectors and file parsers
Versions
Affected: 4.6.0–4.6.8; most also 4.4.0–4.4.18 (ZigBee ZCL / TTL / PEAK CAN TRC 4.6-only). Fixed: 4.6.9 and 4.4.19 (or later).
Exploited in Australia?
unknown
Patch to
Upgrade to Wireshark 4.6.9 or 4.4.19 or later; avoid importing untrusted configuration profiles and opening untrusted capture files until patched

Primary: Wireshark — Security Advisories (wnpa-sec-2026-92…110; 23 Sep 2026) · Vendor: Wireshark wnpa-sec-2026-106 — Profile import crash and possible code execution (CVE-2026-96419) · CVE: CVE-2026-96419, CVE-2026-96416, CVE-2026-96423, CVE-2026-95389, CVE-2026-95391, CVE-2026-96421, CVE-2026-95388, CVE-2026-96415 · Cybersecurity News — Wireshark 4.6.9 fixes 19 vulnerabilities (28 Sep 2026)

vulnerabilities network