CVE-2026-76887: Heap-based Buffer Overflow in Wireshark
Published Aug 19, 2026
·Updated
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
The affected versions are Wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What does exploitation require?
The issue is remotely reachable but has high attack complexity and requires user interaction. No privileges are required, and the stated impact is denial of service through a crash in the dissection engine.