Wireshark 4.6.9 and 4.4.19 Fix a Large Security Batch, Including Profile-Import Code Execution
Wireshark released versions 4.6.9 and 4.4.19 on September 23, 2026, fixing a large batch of security defects across protocol dissectors, capture-file parsers and configuration-profile handling. The most consequential published issue in the batch is CVE-2026-96419, a crafted-profile vulnerability that Wireshark says can crash the application or execute arbitrary code when a user imports a malicious configuration profile.
The Wireshark Foundation recommends upgrading vulnerable installations. Its security advisories list 4.6.9 and 4.4.19 as the fixed versions for the new issues, while the project says it is unaware of exploitation of CVE-2026-96419 and the individual packet-processing flaws reviewed for this release.
For analysts who routinely open packet traces supplied by other people, the update is particularly relevant because many of the fixed dissector and parser defects can be reached through malformed network traffic or capture files. The profile-import flaw has a different trigger: importing a crafted Wireshark configuration profile.
What changed in Wireshark 4.6.9 and 4.4.19
Wireshark's September 23 release notes enumerate a broad security batch. The affected components include protocol dissectors such as ZigBee ZCL, SCTP, IEEE 802.11, X11 and CSN.1, along with capture-file parsers and other input-processing paths.
Examples include CVE-2026-95389, an SCTP dissector crash affecting Wireshark 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18, and CVE-2026-95393, a CSN.1 dissector crash with the same affected ranges. Wireshark says malformed packets injected onto the wire or malicious packet-trace files may trigger those flaws.
The project's security index also lists fixes for issues including a Catapult DCT2000 dissector crash, IEEE 802.11 dissector crash, X11 dissector crash and TIFF dissector infinite loop. Operators should treat the release as a cumulative security update instead of selecting only one CVE to address.
CVE-2026-96419 has the clearest code-execution impact
Wireshark advisory wnpa-sec-2026-106 describes CVE-2026-96419 as a profile-import crash with possible code execution. A crafted configuration profile can cause Wireshark to crash or execute arbitrary code when imported.
The affected ranges are:
| Branch | Vulnerable versions | Fixed version |
|---|---|---|
| Wireshark 4.6 | 4.6.0–4.6.8 | 4.6.9 |
| Wireshark 4.4 | 4.4.0–4.4.18 | 4.4.19 |
Wireshark reports no known exploitation for this issue as of its September 23 advisory. The attack requires convincing a user to import a malformed configuration profile, making profile provenance an important operational control alongside patching.
Packet captures remain an untrusted-input boundary
Several of the other vulnerabilities reinforce an existing operational requirement for packet-analysis environments: capture files and packets obtained from outside a trusted workflow should be handled as untrusted input.
For example, Wireshark says the SCTP and CSN.1 dissector flaws may be triggered either by malformed packets observed on the wire or by opening a malformed packet trace. That matters for SOC analysts, incident responders, malware researchers and support teams that routinely receive captures from customers, compromised hosts or public samples.
Updating the analyzer reduces exposure without changing the underlying workflow. Teams that isolate malware analysis or other hostile-input work should retain those sandboxing and workstation-separation controls after upgrading.
Upgrade guidance
Users on the current 4.6 branch should move to Wireshark 4.6.9 or later. Organizations remaining on the 4.4 branch should install 4.4.19 or later. Wireshark provides current Windows and macOS installers and source code through its official download channel; Linux and Unix users commonly receive Wireshark through their distribution package manager.
Before importing configuration profiles obtained from another party, verify their source. For packet-analysis systems that process externally supplied captures, prioritize the update on analyst workstations and automated processing hosts such as systems running TShark or related Wireshark components.
Wireshark also notes a packaging change relevant to some Unix deployments: extcap binaries are searched under the libexec directory by default in the 4.6 series. The behavior began in 4.6.0 but was documented explicitly in the 4.6.9 notes, and third-party extcap packages may require path adjustments.
Why this release deserves attention
The individual packet-processing flaws are largely denial-of-service class issues in the project's advisories, while CVE-2026-96419 raises the impact to possible arbitrary code execution through a malicious profile import. Together, the fixes cover multiple input surfaces used in real analysis workflows.
Wireshark explicitly attributes the unusually large recent vulnerability volume to a trend in AI-assisted vulnerability reports. That makes 4.6.9/4.4.19 a useful security baseline for organizations that have not updated since earlier 2026 point releases.
Sources
- Wireshark Foundation — 4.6.9 release notes: https://www.wireshark.org/docs/relnotes/wireshark-4.6.9.html
- Wireshark Foundation — security advisories index: https://www.wireshark.org/security/
- Wireshark Foundation — CVE-2026-96419 / wnpa-sec-2026-106: https://www.wireshark.org/security/wnpa-sec-2026-106
- Wireshark Foundation — CVE-2026-95389 / wnpa-sec-2026-93: https://www.wireshark.org/security/wnpa-sec-2026-93
- Wireshark Foundation — September 23 release announcement: https://www.wireshark.org/news/20260923.html