CVE-2026-5402Disclosure(wireshark / wireshark)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch wireshark wireshark systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wireshark

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-06-01)
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
wireshark

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-30: 1Mentions · 2026-05-04: 2Mentions · 2026-05-30: 1Mentions · 2026-06-01: 4Patch / Workaround · 2026-06-01: 3Technical Details · 2026-04-30: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 404-3005-0405-3006-01
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-301
Disclosure1
2026-05-042
Disclosure2
2026-05-301
Disclosure1
2026-06-014
Disclosure1Patch3
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Wireshark 4.6.5 patched over 40 vulnerabilities, including four with possible remote code execution through malformed packets or malicious capture files. TLS, RDP, SBC codec, and profile import flaws (CVE-2026-5402, 5403, 5405, 5656) enable unauthenticated code…

    Post summary

    Wireshark’s latest release (4.6.5) updates over 40 vulnerabilities, including four that could allow unauthenticated remote code execution via malformed packets or malicious capture files, and the release underscores the patch’s importance.

    1000048
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The SOC's Own Weapon: 40+ Wireshark CVEs Including Code Execution (CVE-2026-5402, 5403, 5405, 5656). Wireshark, the world's most widely used open-source network protocol analyzer, released a critical security update on May 3, 2026, addressing a staggering 40+…

    Post summary

    Wireshark issued a critical patch on May 3 2026 covering more than 40 CVEs—including several that allowed code execution—yet no evidence of active exploitation or PoC details was provided.

    1000049
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The RCE flaws are particularly dangerous when Wireshark processes untrusted traffic: TLS Dissector (CVE-2026-5402): Malformed TLS packet causes crash + possible code execution in dissection pipeline SBC Audio Codec (CVE-2026-5403): Crafted SBC audio data triggers parser…

    Post summary

    The post announces two RCE vulnerabilities in Wireshark’s TLS and SBC dissectors, describing how crafted traffic can crash or potentially execute code, without mentioning any PoC, exploit tool, active exploitation, or patch.

    1000045
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-5402 · 4.6.5 → 802.11 The Network Mirror Is the Weapon: Wireshark 4.6.5 Patches 40+ Critical Vulnerabilities Including Remote Code Execution

    Post summary

    The post announces that Wireshark 4.6.5 patches 40+ critical vulnerabilities, including some that allow remote code execution, with no indication of PoC, active exploitation, or false positives.

    1000043
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Four dissectors are vulnerable to code execution via malformed packet injection: TLS Dissector (CVE-2026-5402) — Crash with possible code execution when parsing adversarially crafted TLS traffic RDP Dissector (CVE-2026-5405) — Remote Desktop Protocol packet parsing…

    Post summary

    The announcement lists four protocol dissectors, including TLS and RDP, that are vulnerable to code execution through malformed packet injection, marking a new vulnerability disclosure.

    1000041
    232 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows attackers can exploit protocol dissector vulnerabilities in Wireshark 4.6.4 to achieve code execution, then pivot laterally across network infrastructure. CVE-2026-5402 in the TLS dissector poses the highest risk with potential RCE. Runtime segmentation helps contain post-compromise activity when network analysis tools are targeted. #Vulnerability #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/wireshark-4-6-5-vulnerability-disclosure-2026

    Post summary

    The analysis outlines that Wireshark 4.6.4 contains a critical RCE vulnerability (CVE‑2026‑5402) in the TLS dissector, underscoring the need for immediate attention and mitigation.

    0000052
    1.9K followersView on X
  • Tim Reynolds@__timreynolds
    Disclosure

    @mrezauli @grok TLS Dissector (CVE-2026-5402) — A crash with possible code execution when parsing malformed TLS traffic (wnpa-sec-2026-14) looks interesting - malformed packets are front page now with AI - better start using Scapy

    Post summary

    The post highlights CVE-2026-5402, noting a crash with potential code execution from malformed TLS packets, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000043
    276 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5402 TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution https://www.cve.org/CVERecord?id=CVE-2026-5402

    Post summary

    CVE-2026-5402 is a heap overflow in Wireshark’s TLS dissector that can cause denial of service and potential code execution across versions 4.6.0 to 4.6.4.

    0000085
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwiresharkwireshark---

Explore more