CVE-2026-7785General

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-05-05: 5PoC Mentioned / Linked · 2026-05-05: 1Exploit Tool / Code · 2026-05-05: 1Technical Details · 2026-05-05: 205-05
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Exploit
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Exploit

    🚨 Wireshark MCP Command Injection (CVE-2026-7785) A newly disclosed flaw in wireshark-mcp enables remote OS command injection via the quick_capture function. Attackers can exploit this with no privileges or user interaction, potentially executing arbitrary commands. Public exploit details are already available. ⚠️ Severity: ~7.3 (High) ⚠️ Risk: Remote access → command execution ⚠️ Patch: Not available yet 👉 https://nvd.nist.gov/vuln/detail/CVE-2026-7785 #cybersecurity #infosec #CVE #Wireshark

    Post summary

    Wireshark MCP's quick_capture function is vulnerable to remote OS command injection, with public exploit information already available, but no patch has been released yet.

    0102195
    237 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7785 A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the fun… https://www.cve.org/CVERecord?id=CVE-2026-7785

    Post summary

    The post announces the discovery of CVE-2026-7785 targeting A-G-U-P-T-A wireshark-mcp and links to the official CVE record, but offers no further technical, exploit, or mitigation information.

    00010212
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7785 OS Command Injection in A-G-U-P-T-A Wireshark-MCP Quick Ca... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7785 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces the existence of CVE-2026-7785, noting it involves an OS command injection in A-G-U-P-T-A Wireshark-MCP Quick components, and points to Vulmon for details.

    0000039
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7785 A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the fun… https://www.cve.org/CVERecord?id=CVE-2026-7785 ----- Traducción: CVE-2026-7785 Se … http://infoflow.cloud`

    Post summary

    The text announces the discovery of CVE-2026-7785 in the A-G-U-P-T-A wireshark-mcp component, linking to the official CVE record but providing no additional technical, exploit, or patch information.

    0000033
    75 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7785 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7785 #CVE-2026-7785 #CVE #High #CyberSecurity #InfoSec https://t.co/bTFu7aWhST

    Post summary

    The tweet alerts to CVE-2026-7785 with a high severity rating but offers no technical details, PoC, exploitation code, or patch information.

    0000055
    151 followersView on X

Explore more