As of 3 October 2026. This guide is for small IT teams and technically experienced users who want to update Wireshark while preserving their working configuration. The checks below are editorial recommendations using your own non-sensitive test data, not a software test we performed.
Available releases and the profile import flaw
Wireshark 4.6.9 and 4.4.19 were released on 23 September 2026. The download page lists them as stable and old stable respectively; 4.7.3 is listed separately as a development release. The release notes contain numerous security fixes. A higher version number alone is therefore not a good reason to choose a development build for a work computer. [1] [2] [3] [4]
CVE-2026-96419 (Issue 21553) is particularly relevant when transferring settings: importing a crafted configuration profile can cause a crash or code execution. The vendor identifies 4.6.0–4.6.8 and 4.4.0–4.4.18 as affected, and 4.6.9 and 4.4.19 as fixed. Do not try third-party profile archives as a troubleshooting experiment; use the approved update channel first. The 23 September advisory reports no exploits known to the vendor, not a guarantee that attacks do not exist. Backing up your own profile is no reason to import unverified third-party ZIP files. [5]
Preparation and boundaries
You need installation permission, an operating system supported by the chosen package, backed-up settings and a known non-confidential capture. Do not confuse Windows x64 with ARM64; managed devices must use the approved distribution channel. Work only with network data you are authorized to examine. Captures may contain sensitive information and must not be attached to public bug reports without review. [1]
Six steps for a verifiable transition
- Record the starting point: Wireshark version, operating system, executable path, active configuration, required extensions and capture driver. If several installations exist, identify the path actually being launched.
- Prepare recovery: keep original captures unchanged and back up the personal configuration securely. Profile export skips the default profile and global profiles, so an exported ZIP alone is not a complete settings rollback. [6]
- Choose deliberately: read the official download page and the requirements for that exact version. Select a compatible stable release for normal work. Evaluate development builds or release candidates only in a separate test environment, not by blindly replacing the working installation.
- Stop captures, close Wireshark and update through the approved channel. Review driver and component changes deliberately. Stop if unexpected security warnings appear and verify the source; do not disable protection.
- Restart and confirm the version and executable path. Open a copy of the known test capture and compare packet count, time range, required protocols and saved display filters with recorded expectations. Every packet need not look byte-for-byte identical, but relevant differences need an explanation.
- If live capture is part of the workflow, also make and stop a short authorized test capture on the intended interface. Record the date, version, test case and result. Reading an existing capture does not by itself verify the capture driver.
Troubleshoot safely
If interfaces are missing, ask the responsible IT team to check interface selection, permissions and driver status first. If only one file hangs, preserve the original and compare with the known test file; do not open arbitrary third-party captures. Isolate profile problems with a separate test configuration instead of deleting the working profile. Report reproducible issues with version details and sanitized information. Neither an unverified downgrade nor disabling protection is a universal fix.
Decision and transparency
Accept the transition for the tested workflow when the intended installation starts and file checks, plus capture checks where needed, meet documented expectations. This proves neither absence of bugs nor remediation of every vulnerability. This is a source-based guide, not our own installation, performance or exploit test. No affiliate links or purchase recommendation; the topic reflects editorial timeliness, not a claimed measured surge in search demand.
