PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76885 Wireshark Foundation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T23:16:19.430Z and has not been modified since then. The Tektronix K12xx file parser in Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 crashes when parsing a specific file, allowing for a denial of service attack. This vulnerability affects users who parse Tektronix K12xx files with Wireshark, potentially impacting network protocol analysis and security monitoring capabilities. Affected operators, platform administrators, vulnerability management teams, and security teams should review the official CVE Program record and NVD vulnerability detail pages for updates and monitor vendor advisories for additional information. This vulnerability may require review of compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. The vulnerability has a low CVSS score, indicating a low-priority defensive review is recommended due to limited attack surface and low CVSS score, but defenders should still assess their exposure and plan accordingly. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up, as well as planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Users should also consider performing inventory checks for affected versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7. The likely operational impact of this vulnerability is limited to network protocol analysis and security monitoring capabilities. The source-confidence limits of this vulnerability are based on the official CVE Program record and NVD vulnerability detail pages. The review context for this vulnerability includes the need for defenders to verify Tektronix K12xx file parser usage in their environments and review Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 for potential exposure. The defensive priority for this vulnerability is low, due to the limited attack surface and low CVSS score. However, defenders should still take steps to

Vendor
Wireshark Foundation
Product
Wireshark
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-31
Advisory published
2026-08-19
Advisory updated
2026-08-31

Who should care

Users of Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 who parse Tektronix K12xx files should be aware of this vulnerability, as it may impact their network protocol analysis and security monitoring capabilities. Affected operators, platform administrators, vulnerability management teams, and security teams should review the official CVE Program record and NVD vulnerability detail pages for updates and monitor vendor advisories for additional information. This vulnerability may require review of compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review. The vulnerability has a low CVSS score, indicating a low-priority defensive review is recommended due to limited attack surface and low CVSS score, but defenders should still assess their exposure and plan accordingly. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up, as well as planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Users should also consider performing inventory checks for affected versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7. The debrief provides an executive overview of the vulnerability, which is a denial of service vulnerability in the Tektronix K12xx file parser in Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7. The likely operational impact of this vulnerability is limited to network protocol analysis and security monitoring capabilities. The source-confidence limits of this vulnerability are based on the official CVE Program record and NVD vulnerability detail pages. The review context for this vulnerability includes the need for defenders to verify Tektronix K12xx file parser usage in their environments and review Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 for potential exposure. The defensive priority for this vulnerability is low, due to the limited attack surface and low CVSS score. However, defenders should still take steps to mitigate the vulnerability, such as reviewing official advisories or CVE and

Technical summary

The Tektronix K12xx file parser in Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 crashes when parsing a specific file, allowing for a denial of service attack. This vulnerability affects users who parse Tektronix K12xx files with Wireshark, potentially impacting network protocol analysis and security monitoring capabilities.

Defensive priority

Low-priority defensive review recommended due to limited attack surface and low CVSS score.

Recommended defensive actions

  • Review official CVE Program record and NVD vulnerability detail pages for updates
  • Monitor vendor advisories and source references for additional information
  • Perform inventory checks for affected versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7

Evidence notes

Official CVE Program record and NVD vulnerability detail pages provide limited information about the vulnerability. Further review of vendor advisories and source references may be necessary to determine the full scope of affected systems and potential impact. Defenders should verify Tektronix K12xx file parser usage in their environments and review Wireshark versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 for potential exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76885 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76885

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76885 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76885

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.