Wireshark 4.6.9
Wireshark 4.6.9 fixes 19 security vulnerabilities in protocol dissectors and file parsers, updates more than 30 dissectors, and improves six capture file formats.
Download TAR.XZ Project website ↗Download Mirrors
Wireshark 4.6.9 was released on September 23, 2026. Unlike 4.6.8, this is a security release as much as a maintenance one: it fixes 19 vulnerabilities. We covered it in the news.
Security fixes
The vulnerabilities are in dissectors and file parsers including ZigBee ZCL, SPDY, CSN.1, USB HID, TIFF, X11, RF4CE, MBIM, and IEEE 802.11. A malformed packet on the wire, or a crafted capture file someone sends you, could reach any of them.
That is why the long-standing advice matters: do not run the Wireshark GUI as root. Grant capture rights to dumpcap instead:
sudo dpkg-reconfigure wireshark-common # Debian and Ubuntu
sudo usermod -aG wireshark "$USER"
# log out and back in
Other changes
- More than 30 dissectors updated, including AKP, Bencode, Bluetooth AVCTP, DICOM, F1AP, OpenFlow, QUIC, and ZigBee ZCL
- Better handling of BLF, Network Monitor, pcapng, PEAK TRC, Toshiba, and TTL capture files
- Fixes for SMB object export, Bluetooth AVCTP reassembly, PKCS#12 PBE decryption, and LoRaWAN decryption
Basic usage
# capture on the server, analyze on your desktop
sudo tcpdump -i any -w /tmp/cap.pcap
wireshark /tmp/cap.pcap
# terminal version
tshark -r /tmp/cap.pcap -Y 'dns.flags.response == 0'
Our tcpdump guide and the tcpdump filter builder help with capture filters.
Verify Your Download
Source releases are published with SHA-256 checksums and GPG signatures on the download page.