CVE-2026-3203Patch(wireshark / wireshark)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch wireshark wireshark systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wireshark

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wireshark

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-26: 2Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 202-2502-26
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-262
Patch2
Full discourse3 posts
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Wireshark 4.6.4 ships security fixes for multiple dissector CVEs and restores plugin compatibility Wireshark 4.6.4 fixes three security issues (USB HID memory exhaustion CVE-2026-3201, NTS-KE crash CVE-2026-3202, RF4CE Profile crash CVE-2026-3203) and includes additional stability bug fixes, while also restoring compatibility for plugins impacted by the 4.6.1 API/ABI change. 🎯 Target: Global/Blue Team & DFIR #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.helpnetsecurity.com/2026/02/26/wireshark-4-6-4-released/

    Post summary

    Wireshark 4.6.4 releases a patch that fixes three CVEs (CVE-2026-3201, CVE-2026-3202, CVE-2026-3203) and restores plugin compatibility.

    0101087
    221 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Wireshark 4.6.4 Patches 3 CVEs Causing Dissector DoS/Crashes (USB HID, NTS-KE, RF4CE) Wireshark 4.6.4 fixes three vulnerabilities—CVE-2026-3201 (USB HID memory exhaustion), CVE-2026-3202 (NTS-KE NULL deref crash), and CVE-2026-3203 (RF4CE dissector crash)—that can be triggered by malformed traffic/pcaps to disrupt analysis workflows. 🎯 Target: Global/Network & Security Teams #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/wireshark-4-6-4-released-with-patches-for-multiple-security-vulnerabilities/

    Post summary

    Wireshark 4.6.4 addresses three CVEs—CVE-2026-3201, CVE-2026-3202, and CVE-2026-3203—that cause memory exhaustion or crashes, with the release providing patches for these vulnerabilities.

    0001041
    220 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3203 RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service https://www.cve.org/CVERecord?id=CVE-2026-3203

    Post summary

    CVE-2026-3203 details a crash in Wireshark’s RF4CE Profile protocol dissector that can cause denial of service on affected versions.

    00000112
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwiresharkwireshark---

Explore more