ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow RCE Vulnerability

Executive Summary

A buffer overflow in Wireshark’s RF4CE packet parser allows remote attackers to execute arbitrary code when a user opens a malicious file or visits a malicious page. The vulnerability, identified as CVE-2026-96417, has a CVSS score of 7.8 and was disclosed by Zero Day Initiative.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-23T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.

"Life is 10% what happens to you and 90% how you react to it."

— Charles Swindoll
Source: Zero Day Initiative