Software  When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Wireshark 4.6.6

Wireshark offers powerful, free network packet analysis, letting you capture, inspect, and troubleshoot traffic at a granular level.

Wireshark

Wireshark is a network packet analyzer. A network packet analyzer will try to capture network packets and tries to display that packet data as detailed as possible. You could think of a network packet analyzer as a measuring device used to examine what's going on inside a network cable, just like a voltmeter is used by an electrician to examine what's going on inside an electric cable (but at a higher level, of course). In the past, such tools were either very expensive, proprietary, or both. However, with the advent of Wireshark, all that has changed. Wireshark is perhaps one of the best open source packet analyzers available today.

  • Deep inspection of hundreds of protocols, with more being added all the time
  • Live capture and offline analysis
  • Standard three-pane packet browser
  • Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
  • Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility
  • The most powerful display filters in the industry
  • Rich VoIP analysis
  • Read/write many different capture file formats
  • Capture files compressed with gzip can be decompressed on the fly
  • Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)
  • Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2
  • Coloring rules can be applied to the packet list for quick, intuitive analysis
  • Output can be exported to XML, PostScript®, CSV, or plain text

Wireshark 4.6.6 changelog:

The following vulnerabilities have been fixed:

  • wnpa-sec-2026-51 ROHC protocol dissector crash. Issue 21243.

The following bugs have been fixed:

  • Wireshark crashes when run under Visual Studio on Windows. Work item 24787.
  • Welcome page slide preferences are now available in the preferences window.
  • vwr: Read of uninitialized memory in pntoh16. Issue 16460.
  • vwr: Read of uninitialized memory in find_signature. Issue 16461.
  • Upgrades on Windows do not retain existing optional features unless explicitly requested, resulting in accidental removal of features. Issue 18925.
  • Wireshark.exe version 4.6.5 is twice as large as version 4.6.4. Issue 21233.
  • MACsec dissector global-buffer-overflow. Issue 21235.
  • Wireshark 4.6.5 does not run on Windows 10 version 1809 (including Server 2019 and some LTSC versions) Issue 21237.
  • Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240.
  • packet-bacapp: rename aurth-request to auth-request. Issue 21246.
  • Fuzz job issue: randpkt-2026-05-10-14293434231.pcap. Issue 21253.

New and Updated Features

  • The Windows installers now ship with Npcap 1.88. They previously shipped with Npcap 1.87.

Updated Protocol Support

  • BACapp, BPv7, DB/IB GDS DB, Kafka, MACsec, PFCP, RF4CE, ROHC, RTPS-VT, SAPHDB, and SIP

New and Updated Capture File Support

  • JSON and VeriWave

Plugin Development Changes

  • On UN*X systems (excluding macOS when running from an app bundle, as with the official installer) extcap binaries are now searched for under the libexec directory by default, e.g., /usr/libexec/wireshark/extcap instead of /usr/lib64/wireshark/extcap or similar. This is the customary place for helper binaries, which as opposed to libraries do not need multiarch support. The location can be overridden via the environment variable WIRESHARK_EXTCAP_DIR. The extcap binaries shipped with Wireshark are installed in the new location, but third party extcaps may need packaging changes. This change was effective in version 4.6.0, but was not explicitly noted in the release notes previously. Note that some distributions do not use a libexec directory, such as Alpine Linux, which does not have multilib support. On such systems extcap binaries should be in the same location as before.

Download: Wireshark 4.6.6 | 98.2 MB (Open Source)
Download: Portable Wireshark 4.6.6 | ARM64 Installer
View: Wireshark Website | Screenshot | Release notes

twitter Get alerted to all of our Software updates on Twitter at @NeowinSoftware

Joplin
Next Article

Joplin 3.6.14

LightBulb
Previous Article

LightBulb 2.7.1

0 Comments

Load the comments and join the conversation!

Read the comments, ask the editors questions, show respect and join the conversation.

Click here