VORANT. Threat Intelligence Sign in Create a free account

Wireshark patches multiple RCE and DoS flaws

routine vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory details 19 CVEs in Wireshark before 4.4.19/4.6.9 allowing remote code execution and denial of service.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Wireshark, the widely used network protocol analyzer. The flaws affect Wireshark versions 4.4.x prior to 4.4.19 and 4.6.x prior to 4.6.9, and collectively allow an attacker to trigger remote code execution or remote denial of service, likely through processing of malicious packet captures or crafted network traffic parsed by vulnerable dissectors.

The advisory references 19 separate CVE identifiers and links to 19 corresponding Wireshark security bulletins (wnpa-sec-2026-92 through 110), indicating the issues span multiple protocol dissectors or components rather than a single root cause. No detail on individual dissectors, exploitation vectors, or active exploitation is provided in the advisory itself; defenders should consult the linked Wireshark bulletins for per-CVE specifics.

No in-the-wild exploitation is indicated. Given Wireshark's common use in security operations, incident response, and network engineering, organizations should update to 4.4.19 or 4.6.9 (or later) promptly, particularly on systems where Wireshark is used to open untrusted or externally-sourced capture files, which is the typical exploitation path for this class of vulnerability.

Mentioned in this report

Vulnerabilities CVE-2026-95386CVE-2026-95387CVE-2026-95388CVE-2026-95389CVE-2026-95390CVE-2026-95391CVE-2026-95392CVE-2026-95393CVE-2026-95394CVE-2026-95395CVE-2026-96415CVE-2026-96416CVE-2026-96417CVE-2026-96418CVE-2026-96419CVE-2026-96420CVE-2026-96421CVE-2026-96422CVE-2026-96423

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1221

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,789 reports from 155 sources, 1,534 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs