Wireshark Released Version 4.6.9 to Patch Vulnerabilities
The latest network protocol analyzer update fixes 19 security flaws and expands support for 27 protocols.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security updates provided by open-source software projects?
Wireshark has released version 4.6.9, an update addressing 19 vulnerabilities identified in various dissectors and file parsers. This version also introduces support updates for 27 protocols, including QUIC, ZigBee ZCL, and SMB.
Why it matters
Security patches for widely used network diagnostic tools are critical for maintaining the integrity of traffic analysis in enterprise and research environments. This update ensures compatibility with evolving protocol standards while hardening the software against documented exploits.
The 4.6.9 update resolves 19 vulnerabilities and adds support for 27 protocols, including SMB and ZigBee ZCL. It also fixes specific bugs in PKCS12 PBE decryption and SMB object export.
The players
Wireshark
An open-source network protocol analyzer widely used for packet capture, traffic inspection, and troubleshooting.
The details
The update modifies how the software handles capture files and decodes network traffic. Developers moved Extcap binaries—small interface programs used to provide external packet capture data—to the libexec directory on Unix systems to improve path management. The patch also updates JA4 fingerprint calculations to correctly ignore GREASE (Generate Random Extensions And Sustain Extensibility) values, which are randomized values used to test TLS negotiation logic.
Timeline
August 2026: The prior version, Wireshark 4.6.8, was released.
September 23, 2026: Wireshark 4.6.9 was released to the public.
The Tech Race
Network visibility depends on tools keeping pace with the rapid iteration of the JA4 fingerprinting standard and encrypted protocol updates. This release keeps Wireshark competitive with commercial protocol analyzers by refining how it parses specialized packet data and manages security dependencies.
Users can download the update now via source tarballs, macOS and Windows installers, or through standard Linux software repositories. Systems administrators should note that Unix-based Extcap binaries have been moved to /usr/libexec/wireshark/extcap and may require path adjustments.
The takeaway
Security-focused users should prioritize this update to mitigate the 19 identified parser vulnerabilities. Watch the official project repository for the formal release of CVE documentation related to these specific patches.
Further reading
For more background on how the industry secures diagnostic software, see Cybersecurity.
Source note: This article includes information reported by 9to5Linux.
Live Poll
Do you trust the security updates provided by open-source software projects?






