Executive Summary
On July 8, 2026, Wireshark released version 4.6.7, addressing twelve security vulnerabilities across various protocol dissectors and file parsers. These flaws, present in versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16, could allow attackers to crash the application or consume excessive CPU resources by injecting malformed packets or convincing users to open crafted packet trace files. Affected components include Catapult DCT2000, SSH, IEEE 802.11, Z39.50, UMTS FP, pcapng file reader, and DBS Etherwatch file parser. (wireshark.org)
This release underscores the importance of promptly updating network analysis tools to mitigate potential security risks. The vulnerabilities highlight the need for continuous vigilance in monitoring and updating software to protect against emerging threats.
Why This Matters Now
The recent release of Wireshark 4.6.7 addresses critical vulnerabilities that could be exploited by attackers to crash the application or consume excessive CPU resources. Promptly updating to this version is essential to maintain the security and stability of network analysis operations.
Attack Path Analysis
An attacker crafts a malicious packet or capture file exploiting vulnerabilities in Wireshark's protocol dissectors, leading to application crashes or infinite loops. By convincing a user to open the malicious file, the attacker causes Wireshark to crash, potentially disrupting network analysis activities. The attacker does not gain further access or control over the system, and no data exfiltration occurs.
Kill Chain Progression
Initial Compromise
Description
An attacker crafts a malicious packet or capture file exploiting vulnerabilities in Wireshark's protocol dissectors.
Related CVEs
CVE-2026-15163
CVSS 7.5Multiple protocol dissectors in Wireshark versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 could enter infinite loops when processing malformed packets, leading to excessive CPU consumption.
Affected Products:
Wireshark Foundation Wireshark – 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Exploit Status:
no public exploitCVE-2026-15174
CVSS 5.5The Catapult DCT2000 protocol dissector in Wireshark versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 could crash when processing malformed packets, potentially leading to denial of service.
Affected Products:
Wireshark Foundation Wireshark – 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Exploit Status:
no public exploitCVE-2026-15167
CVSS 5.5The DBS Etherwatch file parser in Wireshark versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 could crash when processing malformed files, potentially leading to denial of service.
Affected Products:
Wireshark Foundation Wireshark – 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Exploit Status:
no public exploitCVE-2026-15172
CVSS 5.5The FMP/NOTIFY protocol dissector in Wireshark versions 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 could enter a large loop when processing certain inputs, leading to excessive CPU consumption.
Affected Products:
Wireshark Foundation Wireshark – 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation for Client Execution
Exploitation for Defense Evasion
Endpoint Denial of Service
Application Layer Protocol
Disabling Security Tools
Indirect Command Execution
Exfiltration Over Alternative Protocol
Impair Defenses
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Establish a process to identify security vulnerabilities
Control ID: 6.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Wireshark vulnerabilities directly impact network security professionals using this critical packet analysis tool for threat detection, incident response, and traffic inspection capabilities.
Information Technology/IT
IT departments relying on Wireshark for network troubleshooting and monitoring face exposure through software vulnerabilities affecting their primary network analysis infrastructure.
Financial Services
Financial institutions using Wireshark for network security compliance and encrypted traffic analysis face risks to their critical infrastructure monitoring and regulatory requirements.
Health Care / Life Sciences
Healthcare organizations utilizing Wireshark for network security and HIPAA compliance monitoring are vulnerable to compromised packet analysis affecting patient data protection.
Sources
- Wireshark 4.6.7 Released, (Sat, Jul 11th)https://isc.sans.edu/diary/rss/33146Verified
- Wireshark 4.6.7 Release Noteshttps://www.wireshark.org/docs/relnotes/wireshark-4.6.7.htmlVerified
- Wireshark 4.6.7 patches a dozen security flawshttps://www.helpnetsecurity.com/2026/07/09/wireshark-4-6-7-released/Verified
- Wireshark 4.6.7 Fixes 12 Security Flaws Across Protocolshttps://thecyberexpress.com/wireshark-4-6-7/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can limit the impact of application crashes caused by malicious packets, thereby reducing potential disruptions in network analysis activities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to deliver malicious packets to the target workload would likely be constrained, reducing the risk of exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of further system compromise.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of further system compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.
The impact of the attack would likely be limited to the targeted workload, reducing the risk of widespread disruption.
Impact at a Glance
Affected Business Functions
- Network Analysis
- Security Monitoring
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Regularly update Wireshark to the latest version to mitigate known vulnerabilities.
- • Implement strict input validation and sanitization to prevent processing of malformed packets.
- • Utilize intrusion prevention systems to detect and block malicious network traffic.
- • Educate users on the risks of opening untrusted capture files.
- • Monitor network traffic for anomalies that may indicate exploitation attempts.



