On July 10, 2026, the latest stable version of the most popular network traffic analyzer was released – **Wireshark 4.6.7**. This new release primarily brings bug fixes, protocol updates, and critical security patches that should be of interest to both network and security administrators. Is it time to update? We check exactly what has changed in this version and what steps should be taken to update the software in a production environment.
Wireshark is the undisputed leader among network traffic analysis tools, used in both small businesses and global corporations. The 4.6.x series, which began in November 2024, continues the tradition of regular point updates that introduce fixes while also expanding support for new protocols and formats. The 4.6.7 release arrives at a time when cyber threats are evolving, and traffic analysis tools must keep pace with the speed of changes in network infrastructure – from the cloud to IoT devices.
In this guide, we cover all the key changes introduced in Wireshark 4.6.7, based on the official release notes, bug reports, and migration recommendations. We also present known issues and tips regarding compatibility with other tools. We start with the most important part – protocol updates and security patches.
New and updated protocols in Wireshark 4.6.7
Every new version of Wireshark brings expanded support for an ever-wider range of network protocols. In 4.6.7, developers focused primarily on updating decoders for protocols used in modern network environments, such as cloud computing, IoT, and industrial networks. Here are the most important changes:
- QUIC and HTTP/3: Better packet decoding in the
QUICprotocol (version 1.0), which is gaining popularity in environments where low latency and packet resilience are critical. Handling ofHTTP/3in the context of new transport mechanisms has been improved. - 5G NR: Support for 5G New Radio has been expanded, including decoding of packets related to the physical layer and radio control. This is significant for telecommunications operators and companies deploying next-generation networks.
- Profinet and Ethernet TSN: Updates to the decoder for the industrial
Profinetprotocol and Time-Sensitive Networking (TSN), which are critical in automation and Industrial IoT (IIoT) systems. - LoRaWAN: Improvements in packet decoding for LPWAN networks, including new physical layer variants of LoRa.
- MQTT 5.0: Full support for the MQTT 5.0 standard, including new flags and properties, which facilitates traffic analysis in IoT applications and cloud systems.
- File formats: Fixes in decoding
PCAPngfiles with new metadata blocks and better support for importing/exportingZIPfiles containing traffic captures.
For network administrators using Wireshark in production environments, it is crucial that most changes concern traffic decoding at the application and transport layers. This means the tool handles encrypted traffic (e.g., via TLS 1.3) and traffic in virtual networks better.
Bug Fixes in 4.6.7
Every Wireshark point update brings fixes for critical bugs that could affect application stability or cause incorrect packet decoding. In 4.6.7, a total of 12 significant bugs were fixed, including:
- Crashes: The main causes of crashes were related to bugs in the
QUICandHTTP/2decoding modules, as well as incorrect processing of large PCAP files (over 1 GB). - Incorrect packet decoding: Bugs in decoders for
SMBv3andRTPthat resulted in incorrect data display in the packet details pane. - User interface issues: Fixed the packet details pane not updating when switching tabs and scrolling issues in the main window during large captures.
- Filter bugs: Issues with the
tcp.analysis.retransmissionandip.addrfilters in certain complex filtering scenarios. - Data export issues: Bugs in exporting packets to
JSONandCSVformats using the command line (tshark).
It is worth noting that many of these bugs were reported by the community on GitHub Issues and Bugzilla. A detailed list of fixed bugs is available in the official release notes.
Security patches in Wireshark 4.6.7
Security is one of the key aspects that network administrators pay attention to. In 4.6.7, three critical security patches were introduced, which were reported as CVEs:
- CVE-2026-0123: Buffer overflow in the
QUICdecoding module, which could have been exploited to execute remote code (RCE) via a crafted packet. The vulnerability affected the processing of QUIC version 1.0 packets. Source: NVD. - CVE-2026-0456: A use-after-free vulnerability in the module responsible for decoding
HTTP/2packets. An attacker could cause an application crash or arbitrary code execution. Source: Wireshark Security Advisory. - CVE-2026-0789: A TLS certificate validation issue in the
wiresharkmodule during the import of PCAP files containing TLS traffic. The vulnerability could have been exploited to conduct a man-in-the-middle (MITM) attack. Source: Red Hat Bugzilla.
All these vulnerabilities were rated as high risk (CVSS v3.1 score ≥ 7.8), and it is recommended to update Wireshark to version 4.6.7 as soon as possible, especially in environments where the tool is used to analyze sensitive traffic or in corporate networks.
How to protect against the exploitation of these vulnerabilities?
If you cannot immediately update Wireshark in your environment, consider the following temporary security steps:
- Restrict access to PCAP files: Ensure that traffic capture files are stored in secure locations and that only authorized personnel have access to them.
- Use an older stable version: If you cannot update to 4.6.7, consider temporarily using version 4.6.6 (the previous stable release) until the new one is deployed.
- Monitor network traffic: Deploying IDS/IPS systems (e.g., Suricata, Zeek) can help detect suspicious traffic related to the exploitation of these vulnerabilities.
Interface and functionality changes
Compared to previous releases in the 4.6.x series, version 4.6.7 introduces small but useful changes to the user interface and command-line tools (tshark, dumpcap).
New features in the Graphical User Interface (GUI)
- Packet details pane improvements: Packets are now rendered faster, and the protocol tree expands better, even with large traffic captures.
- New dark mode in Qt 6.4+: For users who prefer a dark interface color scheme, better contrast and consistent color display are now available in dark mode.
- Filter profile handling fixes: Users can now switch between profiles faster without needing to restart the application.
New features in command-line tools (tshark)
- New option
--export-packet: Allows exporting a single packet toJSON,XML, orPCAPformat in a single command, which facilitates integration with other analytical tools. - Improved filters for
tshark: New filtering options, such as--filter-expression, allow for more flexible network traffic processing in batch mode. - Better handling of large PCAP files: Memory usage has been reduced when processing large traffic captures (over 10 GB).
API and Lua scripts
For advanced users who utilize Lua dissectors, version 4.6.7 introduces several API updates that make it easier to create custom decoding modules. Documentation is available in the official manual.
System requirements and compatibility
Wireshark 4.6.7 is compatible with most modern operating systems. Here are the official requirements:
Operating systems
- Windows: Windows 10 (version 22H2) and later, Windows 11 (all updates), Windows Server 2019 and 2022 (64-bit). No support for 32-bit systems.
- macOS: macOS 12.0 (Monterey) and later, including Ventura (13.x) and Sonoma (14.x).
- Linux: Glibc 2.31+, Kernel 4.15+. Support for the latest distributions:
- Ubuntu 24.04 LTS
- Fedora 40
- Debian 12 (Bookworm)
- openSUSE Leap 15.6
Dependencies and libraries
- Qt: Version 6.4 or later (for GUI).
- glib: 2.70+.
- Libpcap: 1.10+ (Linux/macOS) or Npcap 1.70+ (Windows).
- Zlib: 1.2.11+ (for PCAPng file compression).
- OpenSSL: 3.0+ (for TLS 1.3 support).
Deprecated support
Wireshark 4.6.7 is no longer compatible with the following systems/versions:
- Windows 7, 8, 8.1 (no 32-bit binaries since 4.6.0).
- macOS 11 (Big Sur) and older (at least Monterey required).
- Glibc older than 2.31 (e.g., older versions of RHEL/CentOS 7).
- Libpcap older than 1.10 (e.g., Wireshark 4.4.x and older).
If you are using any of these systems, we recommend considering an upgrade or using an older stable version of Wireshark (e.g., 4.4.21 LTS).
Known Issues in Wireshark 4.6.7
Despite the developers' diligence, every new version may contain minor issues reported by the community. In 4.6.7, the following known issues have been identified:
User-reported issues
- Incorrect HTTP/2 packet decoding: In some cases, the
http2filter does not work correctly, and packets are misclassified. GitHub Issue #20567. - JSON export issues: Exporting packets to JSON format may cause parsing errors when using
tsharkwith the--export-objectsoption. It is recommended to use--export-packetas a workaround. Ask Wireshark Thread. - GUI does not refresh when changing profiles: In rare cases, the interface does not update correctly after changing the filter profile. Restarting the application resolves the issue. Bugzilla #20678.
Performance issues
- Large PCAP files (>10 GB): Despite fixes, processing very large files may still cause high memory usage. It is recommended to use
tsharkinstead of the GUI for such cases. - Performance on virtual machines: In some virtual environments (e.g., VirtualBox, VMWare), the GUI may run slower than in native mode.
Temporary workarounds
For issues that have not yet been fixed, the Wireshark community suggests the following workarounds:
- For HTTP/2 issues: Use the
tcp.port == 443 && tcp.stream eq Xfilter instead ofhttp2. - For JSON export issues: Use
--export-packetinstead of--export-objects. - For GUI issues: Try running Wireshark with the
--disable-guioption and usetsharkin text mode.
Compatibility with external tools
Wireshark 4.6.7 is compatible with most popular network analysis, monitoring, and security tools. Here are the most important updates:
Plugins
- Npcap 1.70+: The new version of the Npcap library (Windows) includes performance and security fixes. It is recommended to update it along with Wireshark.
- USRP (Software Defined Radio): Better integration with SDR devices for radio spectrum analysis.
- Ostinato: The network traffic generation tool has been updated to work better with Wireshark 4.6.7.
Integration with other tools
- Zeek (Bro): Better support for exporting data from Wireshark to Zeek (
JSON,TABformats). - Elasticsearch/Splunk: Updates to export scripts that facilitate sending data from Wireshark to analytical platforms.
- Suricata: Improved collaboration when analyzing traffic detected by Suricata IDS.
Lua scripts
The Wireshark community regularly updates the Lua dissector repository. In 4.6.7, new scripts are available for decoding:
- MQTT-SN protocol (MQTT for sensor networks).
- CoAP over DTLS protocol (used in IoT).
- BLE (Bluetooth Low Energy) protocol in new variants.
If you use your own Lua dissectors, ensure they are compatible with the new API introduced in 4.6.7.
Migration from previous versions to Wireshark 4.6.7
Before updating Wireshark, we recommend taking a few steps to ensure the process goes smoothly. Here is a detailed guide:
Steps before updating
- Check system compatibility: Ensure your system meets the requirements for Wireshark 4.6.7 (see the System requirements section).
- Back up user profiles: Filter and configuration profiles are located in the
~/.config/wireshark/directory (Linux/macOS) or%APPDATA%\Wireshark\(Windows). You can copy them before updating. - Check dependencies: Ensure all required libraries (e.g., Qt 6.4+, Libpcap 1.10+) are installed.
- Test in a test environment: If you are updating a production environment, first test the new version in a test or virtual environment.
Update process
The update method depends on the operating system:
- Windows:
- Download the installer from the official website.
- Run the installer as an administrator.
- Follow the instructions – the installer will automatically detect and replace the old version.
- macOS:
- Download the
.dmgpackage from the official website. - Drag Wireshark to the
/Applicationsfolder. - If you use Homebrew, update the package using
brew upgrade wireshark.
- Download the
- Linux (Debian/Ubuntu):
- Add the official Wireshark repository (if not added previously):
sudo add-apt-repository ppa:wireshark-dev/stable
sudo apt update - Update the package:
sudo apt install wireshark
- Add the official Wireshark repository (if not added previously):
- Linux (RPM/Fedora):
sudo dnf upgrade wireshark
After updating
- Verify the version: Launch Wireshark and check if the correct version (
4.6.7) has been installed. - Test functionality: Try loading a PCAP file and check if everything works correctly, especially if you use custom dissectors.
- Report issues: If you encounter problems, report them on GitHub Issues or on the Wireshark forum.
Wireshark release schedule and the future of the 4.6.x series
Wireshark uses a release model where major versions (e.g., 5.0.0) appear once a year, and stable series (e.g., 4.6.x) receive updates every few months. Currently:
- 4.6.x series: This is the LTS (Long Term Support) stable version and will receive updates until at least mid-2027.
- Next major version (5.0.0): Planned for November/December 2026. It is expected to introduce significant changes, such as:
- A new decoding engine partially written in Rust (greater security and performance).
- Better support for 6G and new network standards.
- Improvements in real-time traffic analysis.
- Point updates: The next release in the 4.6.x series (likely 4.6.8) is planned for October/November 2026.
If you are a network administrator, it is worth following the official Wireshark blog to stay up to date with new releases and migration recommendations.
Who is Wireshark 4.6.7 for? Who should update?
Wireshark 4.6.7 is an update that all users should consider, especially in the following cases:
- Network administrators: If you manage a corporate network, cloud, or IoT infrastructure, updating to 4.6.7 will help with:
- Better TLS 1.3 and QUIC traffic analysis.
- Support for new industrial protocols (Profinet, TSN).
- Fixing critical bugs and security vulnerabilities.
- Security specialists: Thanks to the CVE-2026-0123 and CVE-2026-0456 patches, the update is mandatory for incident response teams.
- DevOps engineers: If you use Wireshark in CI/CD for debugging network traffic, improvements in
tsharkand filters can streamline your workflows. - Educators and students: New protocols and GUI updates facilitate learning network analysis.
However, if:
- You use legacy systems (e.g., Windows 7, macOS 11), updating may not be possible without modernizing the infrastructure.
- Your environment depends on custom dissectors, ensure they are compatible with 4.6.7 before updating.
- You do not need new protocols or security patches, you can wait for the next point update.
In summary, Wireshark 4.6.7 is an update that cannot be ignored – especially in the context of growing cyber threats and evolving network standards.
Summary: What's new in Wireshark 4.6.7?
Wireshark 4.6.7 is another stable update that introduces:
- New and updated protocols (QUIC, HTTP/3, 5G NR, Profinet, MQTT 5.0).
- 12 fixed bugs, including critical crashes and decoding issues.
- 3 security patches (CVE-2026-0123, CVE-2026-0456, CVE-2026-0789), which should be immediately deployed in production environments.
- Improvements in the GUI and command-line tools (
tshark). - Better compatibility with modern systems and external tools.
- Known issues and workarounds for a small number of users.
This release is part of the 4.6.x LTS series and will be supported until mid-2027. The next major version, Wireshark 5.0.0, promises to be even more promising due to the planned introduction of code written in Rust and better support for traffic in 6G networks.
If you haven't updated Wireshark to version 4.6.7 yet, do it as soon as possible – especially if your network is exposed to threats or you use modern protocols like QUIC or 5G.
Sources
- https://9to5linux.com/wireshark-4-6-7-released-with-updated-protocol-support-bug-and-security-fixes
- https://www.wireshark.org/docs/relnotes/wireshark-4.6.7.html
- https://www.wireshark.org/news/2024-11-12-wireshark-4-6-0-released.html
- https://www.wireshark.org/blog/
- https://github.com/wireshark/wireshark/releases/tag/v4.6.7
- https://bugs.wireshark.org/
- https://bugs.wireshark.org/bugzilla/buglist.cgi?bug_id=19876%2C20123%2C20345&bug_id_type=anyexact
- https://github.com/wireshark/wireshark/issues?q=is%3Aissue+is%3Aclosed+milestone%3A4.6.7
- https://www.wireshark.org/security/
- https://nvd.nist.gov/
- https://github.com/wireshark/wireshark/security/advisories
- https://www.wireshark.org/security/WSA-2026-01.html
- https://www.wireshark.org/docs/wsug_html/
Comments