Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Wireshark 4.6.9: Security Enhancements Address 19 Flaws

Wireshark 4.6.9: Security Enhancements Address 19 Flaws

Posted on September 28, 2026 By CWS

Wireshark has announced the release of version 4.6.9, a critical update aimed at addressing 19 identified vulnerabilities, including those in protocol dissectors and capture-file parsers. Released on September 23, this update coincides with version 4.4.19 and is available as installers for Windows and macOS, as well as source code. This update is crucial for users who rely on Wireshark for comprehensive network protocol analysis.

Key Vulnerabilities and Fixes

The most pressing vulnerability addressed in this release is CVE-2026-96419, identified as wnpa-sec-2026-106. This flaw could lead to application crashes or even arbitrary code execution if a user imports a specially crafted configuration profile. This vulnerability has been present in versions 4.6.0 through 4.6.8 and in the 4.4 branch from 4.4.0 through 4.4.18. The new release mitigates these risks.

Although there is no evidence of active exploitation, the potential for harm remains significant. A malicious profile could be distributed via phishing, shared analysis packages, or untrusted repositories, posing as a legitimate troubleshooting tool.

Additional Security Enhancements

Beyond the most critical vulnerabilities, the update also addresses issues such as application crashes, memory leaks, and denial-of-service conditions. These problems can occur during the processing of malformed data, affecting components like ZigBee ZCL, SCTP, SPDY, and several others. Notably, crafted captures could cause infinite loops or excessive resource consumption in the application.

The update also fixes bugs such as a DICOM heap overwrite, Bluetooth AVCTP integer overflows, and a stack-based buffer overflow in etwdump. These corrections are essential for ensuring parser reliability and accurate forensic analyses by security operation centers (SOCs).

Recommendations for Immediate Action

It is advised that organizations promptly upgrade to Wireshark 4.6.9 or the latest version of the 4.4 branch to safeguard against potential threats. Until these updates are applied, analysts should avoid using unverified profiles or capture files, and consider isolating risky analyses in secure environments.

Administrators should also review the configurations of analyst workstations, jump boxes, and other critical systems. Official update packages are available on Wireshark’s download page, ensuring users have access to the most secure version.

This update underscores the importance of maintaining up-to-date software to protect against evolving cybersecurity threats. By addressing these vulnerabilities, Wireshark continues to provide a reliable tool for network analysis and security investigations.

Cyber Security News Tags:configuration profile, CVE-2026-96419, Cybersecurity, IT security, malicious packet, network protocol, network security, protocol analyzer, security flaws, Sharkd utility, SOC teams, software update, software vulnerabilities, vulnerability patch, Wireshark

Post navigation

Previous Post: New Windows Attack Bypasses EDR with Process Injection

Related Posts

American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Cyber Security News
VMware Fusion Flaw Allows Root Access Escalation VMware Fusion Flaw Allows Root Access Escalation Cyber Security News
AI-Driven Threat Exploits Google Discover to Spread Malware AI-Driven Threat Exploits Google Discover to Spread Malware Cyber Security News
Microsoft Exchange Online Service Down Microsoft Exchange Online Service Down Cyber Security News
Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover Cyber Security News
Phishing Scam Targets Job Seekers via Fake Recruiter Emails Phishing Scam Targets Job Seekers via Fake Recruiter Emails Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Wireshark 4.6.9: Security Enhancements Address 19 Flaws
  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities
  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Wireshark 4.6.9: Security Enhancements Address 19 Flaws
  • New Windows Attack Bypasses EDR with Process Injection
  • Citrix Urges Immediate Update for NetScaler Vulnerabilities
  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark