ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed a Wireshark RF4CE parsing buffer overflow enabling remote code execution, CVE-2026-96417.
ZDI-26-747 describes a buffer overflow in Wireshark's RF4CE packet parser that could let a remote attacker run arbitrary code. Exploitation requires the target to open a malicious capture or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-96417. No in-the-wild exploitation is mentioned.