ZeroHour

Vulnerabilities

619 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76886
Heap-based buffer overflow in Wireshark C12.22 dissector enables denial of service

CVE-2026-76886 is a heap-based buffer overflow (CWE-122) in the C12.22 protocol dissector of the Wireshark network protocol analyzer, affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when a vulnerable Wireshark or tshark instance dissects a maliciously crafted C12.22 packet, whether from live network traffic during a capture or from an attacker-supplied capture file. An attacker who can get such a packet into a capture session gains denial of service, crashing the analyzer and interrupting capture/analysis; the CVE is rated 9.8 (critical) under CVSS 3.1, although the described impact is limited to a dissector crash. Anyone running the listed Wireshark versions is affected, particularly analysts capturing on networks where third parties can inject traffic or processing untrusted capture files. Exploitation has not been reported in the wild; the bug is tracked in public GitLab issues, is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

Do: Upgrade Wireshark to the first release after 4.6.7 in the 4.6 branch or after 4.4.18 in the 4.4 branch as soon as the patch releases are available. Until then, disable the C12.22 dissector via Analyze > Enabled Protocols, and avoid running automated tshark/capture jobs or file-formatting analysis on untrusted traffic or capture files from untrusted sources.

9.8
group max
<1% PoC ×2
  • wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
massmillions of Wireshark installations on the 4.4.x/4.6.x branches, though only hosts dissecting attacker-controlled C12.22 traffic are realistically triggerable
CVE-2026-19694
+2 in the same advisory: …19696 …19695
Heap buffer overflow in Wireshark TTX Logger parser causes crash DoS

Wireshark versions 4.6.0 through 4.6.7 contain a heap-based buffer overflow (CWE-122) in the TTX Logger file parser, the component used to read TTX Logger capture files. The flaw is triggered when the parser processes a crafted or malformed TTX Logger file, and the CVSS vector (local attack vector, user interaction required) means an attacker needs a local user to open the malicious file. Successful exploitation crashes the application, producing a denial of service with no confidentiality or integrity impact. Anyone running Wireshark 4.6.0 through 4.6.7 is affected, especially users who open capture files obtained from untrusted sources. No in-the-wild exploitation is known: the issue is documented with a public PoC reference on the Wireshark GitLab tracker, EPSS is 0.1% (3rd percentile), and it is not in CISA KEV.

Do: Check the installed Wireshark version and upgrade to a release newer than 4.6.7 when available from wireshark.org. As an interim mitigation, do not open TTX Logger capture files from untrusted or unexpected sources with affected 4.6.x builds; the flaw only causes a crash, so risk is limited to availability.

5.5<1% PoC
  • Wireshark 4.6.0 through 4.6.7
massmillions of desktop installations (Wireshark is the de facto standard free packet analyzer, and 4.6.x is the current release branch)
CVE-2026-15169
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • wireshark wireshark
CVE-2026-9759
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

NVD description · AI analysis pending
5.5<1%
  • wireshark wireshark
CVE-2026-6525
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

NVD description · AI analysis pending
5.5<1% PoC
  • wireshark wireshark
CVE-2026-5656
+3 in the same advisory: …5405 …5403 …5404
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • wireshark wireshark
CVE-2026-6538
+3 in the same advisory: …6870 …6869 …6867
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

NVD description · AI analysis pending
5.5<1% PoC
  • wireshark wireshark