Skip to content

// #pcap

1 article

🔬 Assessment

Wireshark CVE-2026-5656 — Remote Code Execution via Malicious PCAP File, Update to 4.4.6

A code execution vulnerability in Wireshark's PCAP/PCAPNG file parser allows a malicious capture file to trigger arbitrary code execution when opened by an analyst. CVE-2026-5656 affects all Wireshark versions prior to 4.4.6 across Windows, macOS, and Linux. The attack vector is especially concerning for security teams that open externally-sourced capture files during incident response or threat hunting — update Wireshark to 4.4.6 immediately.

#wireshark +6