# Wireshark patches multiple RCE and DoS flaws

Published: 2026-09-24 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/e510aebf-0219-523e-8a46-c301bfb9a930/wireshark-patches-multiple-rce-and-dos-flaws

> CERT-FR advisory details 19 CVEs in Wireshark before 4.4.19/4.6.9 allowing remote code execution and denial of service.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Wireshark, the widely used network protocol analyzer. The flaws affect Wireshark versions 4.4.x prior to 4.4.19 and 4.6.x prior to 4.6.9, and collectively allow an attacker to trigger remote code execution or remote denial of service, likely through processing of malicious packet captures or crafted network traffic parsed by vulnerable dissectors.

The advisory references 19 separate CVE identifiers and links to 19 corresponding Wireshark security bulletins (wnpa-sec-2026-92 through 110), indicating the issues span multiple protocol dissectors or components rather than a single root cause. No detail on individual dissectors, exploitation vectors, or active exploitation is provided in the advisory itself; defenders should consult the linked Wireshark bulletins for per-CVE specifics.

No in-the-wild exploitation is indicated. Given Wireshark's common use in security operations, incident response, and network engineering, organizations should update to 4.4.19 or 4.6.9 (or later) promptly, particularly on systems where Wireshark is used to open untrusted or externally-sourced capture files, which is the typical exploitation path for this class of vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2026-95386, CVE-2026-95387, CVE-2026-95388, CVE-2026-95389, CVE-2026-95390, CVE-2026-95391, CVE-2026-95392, CVE-2026-95393, CVE-2026-95394, CVE-2026-95395, CVE-2026-96415, CVE-2026-96416, CVE-2026-96417, CVE-2026-96418, CVE-2026-96419, CVE-2026-96420, CVE-2026-96421, CVE-2026-96422, CVE-2026-96423

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1221

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e510aebf-0219-523e-8a46-c301bfb9a930/wireshark-patches-multiple-rce-and-dos-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
