Wireshark 4.6.8 brings an extensive set of security fixes, addressing 28 vulnerabilities and 25 other bugs. The update concerns the popular network protocol analyzer and is recommended for those who open log files or examine untrusted traffic.

The SANS Internet Storm Center announcement lists the release as August 16, while the official project notes describe the individual fixes. Wireshark is not a service that is typically exposed directly to the internet, but it processes data that may have been generated by third parties.
See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities
What Wireshark 4.6.8 fixes
The official documentation for the release lists issues ranging from the Bluetooth AVRCP and HFP parsers to the SSH, Kerberos, RDP, CMS, RRC, and X.509IF protocols. Most of the descriptions concern the parser crashing when processing specially crafted packets or log files.
The fixes also cover file readers for pcapng, Gammu DCT3, Catapult DCT2000, Tektronix K12xx, and BLF. In some cases the problem concerns the packet reassembly mechanism, while in others a specific protocol parser or the sharkd utility.
The list is important because Wireshark supports a large number of protocols and capture formats. A file that appears harmless to a user can trigger a different code path depending on its content. The fixes don't just apply to the graphical application, but also to individual tools used in servers or automation pipelines.
The official Wireshark security advisories shows that several of the fixes are available in both the 4.6.8 and 4.4.18 series. For advisory wnpa-sec-2026-90, which concerns the Gammu DCT3 analyzer, the fixed version is 4.6.8, while wnpa-sec-2026-91 concerns the Bluetooth AVRCP analyzer.

How can the risk arise?
A maliciously crafted log file or malformed packet can lead to an unexpected application termination when analyzed by a vulnerable version. The result does not automatically mean remote code execution, but it can interrupt an audit process, delay incident analysis, or affect an automated system using Wireshark tools.
Special care is needed in groups that exchange pcapng files, in malicious traffic analysis labs, and on stations where the TShark or sharkd utilities are used. Reading data from an unknown source should be done in a controlled environment, even after installing the update.
The fact that several tips describe a crash does not diminish their importance. In an operations center, a breakdown of an analysis station can leave an incident uncontrolled at a time when analysts need a quick picture of the traffic. The installation of the release should therefore be part of the update management process.
See also: GitLab fixes 8 security vulnerabilities in CE and EE

The recommended update
Wireshark says anyone using a vulnerable version should consider upgrading. Wireshark 4.6.8 is the stable release of the 4.6 series, while 4.4.18 covers organizations that remain on the 4.4 series. Administrators should confirm which version their distribution supports and schedule an installation from the official packages.
After the upgrade, it is necessary to check the automations that call TShark or sharkd, as well as the third-party tools that read the capture files. At the same time, it is useful to limit access to untrusted files and keep the original data in backup copies, so that the technical team can safely repeat the analysis.
See also: Wireshark 4.6.7 fixes 12 security issues across multiple protocols
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The SecNews technical team recommends updating before the next use of logs from external sources. The 28 fixes do not all address the same attack scenario, but the range of affected analysts makes the upgrade a practical measure with immediate benefit.
