CVE-2026-5404Disclosure(wireshark / wireshark)

LOWCVSS 5.5 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for wireshark wireshark systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wireshark

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-01); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
wireshark

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-05-01: 4Mentions · 2026-05-03: 1Active Exploitation · 2026-05-03: 1Technical Details · 2026-05-01: 205-0105-03
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-014
Disclosure2General2
2026-05-031
Active Exploitation1
Full discourse5 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Active Exploitation

    A critical 0-day vulnerability (CVE-2026-5404) is currently in the wild, and there is no official patch available yet. This exploit allows attackers to silently infiltrate systems without leaving a footprint. Is your infrastructure hardened against this? #cybersecurity #zeroday #cve #infosec #devsecops #Hacking #linux #cyberthreats #developers #sysadmin #vulnerability #wireshark

    Post summary

    The post claims CVE‑2026‑5404 is a critical 0‑day being actively exploited in the wild with no patch yet, urging defenders to assess resistance.

    11011331
    889 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5404 📊 Severity: 4.7 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5404 #CVE-2026-5404 #CVE #Medium #CyberSecurity #InfoSec https://t.co/QWOlaRmHie

    Post summary

    The tweet provides a brief CVE alert with severity and impact notes but lacks technical details, exploit information, or patch guidance.

    1000027
    151 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-5404 K12 RF5 File Parser Crash Denial of Service in Wireshark 4.6.0-4.6.4 and 4.4.0-4.4.14 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5404

    Post summary

    The entry references CVE-2026-5404, noting a crash in Wireshark’s K12 RF5 File Parser for certain versions, but provides no PoC, exploit, patch, or technical detail beyond the version information.

    0001052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5404 K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service https://www.cve.org/CVERecord?id=CVE-2026-5404 ----- Traducción: CVE-2026-5404 Caída del analizador de archivos RF5 K12 en Wireshark 4.6.0 a 4.6.4 y 4.4.0… http://infoflow.cloud`

    Post summary

    The entry reports a new CVE (CVE‑2026‑5404) that triggers a crash in Wireshark’s K12 RF5 file parser, leading to a denial‑of‑service condition on the listed version ranges.

    0000023
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5404 K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service https://www.cve.org/CVERecord?id=CVE-2026-5404

    Post summary

    The text announces CVE‑2026‑5404, a denial‑of‑service vulnerability in Wireshark affecting specific versions, without mentioning active exploitation or mitigation details.

    00000163
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwiresharkwireshark---

Explore more