The popular network analyzer Wireshark released version 4.6.8 on 13 August 2026. The maintenance update is above all security-relevant: it closes 28 vulnerabilities (WNPA-SEC-2026-64 to -91), nine of which can be triggered simply by opening a saved capture file.
Most of the flaws involve crashes in protocol dissectors – the components Wireshark uses to break down individual protocols. Affected dissectors include those for RDP, Kerberos, SSH and several Bluetooth protocols. Because many of the bugs can be triggered via manipulated capture files, anyone who opens third-party captures should be especially careful.
Specific fixes
- Stack buffer overflow in the K12/RF5 writer.
- Out-of-bounds read in the BLF writer when handling truncated, VLAN-tagged Ethernet frames.
- NULL-pointer dereference in the decryption path of the KNXIP Secure Wrapper.
On top of that come numerous fixes for handling file formats such as pcapng, Endace ERF and Vector BLF. Windows users also benefit from two convenience fixes: the “Capture File Properties” had been slowing the app down since 4.6.6, and toggling the TCP setting for analysing sequence numbers caused a crash. An update is recommended for all users.
Sources: Wireshark Release Notes, Help Net Security.



















