Skip to content
New NatJack Research Exposes Design Weaknesses Across Major NAT Implementations

New NatJack Research Exposes Design Weaknesses Across Major NAT Implementations

Manilatimes August 6, 2026

At Black Hat 2026, Synack Red Team researcher Malcolm Stagg reveals NatJack, a previously unrecognized attack class exploiting design assumptions in network address translation

New NatJack Research Exposes Design Weaknesses Across Major NAT Implementations

At Black Hat 2026, Synack Red Team researcher Malcolm Stagg reveals NatJack, a previously unrecognized attack class exploiting design assumptions in network address translation.

Stagg conducted the research over several years and is jointly crediting Synack Red Team along with his own research handle Sodium-24, of SODIUM-24, LLC. The research identifies four distinct techniques attackers can use against NAT devices: hijacking active TCP connections, poisoning DNS responses, identifying the ports assigned to other connections, and forcing denial of service by exhausting a device's NAT table. Two CVEs have been assigned to date ( CVE-2026-56181 , affecting Microsoft Windows NAT in Hyper-V, and CVE-2026-63913 , affecting the Linux netfilter conntrack subsystem). Additional vendor advisories or CVE assignments may follow as coordinated disclosure continues. Independent testing found the underlying flaw present across NAT implementations from multiple vendors using entirely independent codebases, including Windows, Linux, and macOS.

Unlike vulnerabilities tied to a specific coding error, NatJack stems from a design assumption, that devices sharing a NAT table can trust one another, that held for most of the internet's history but no longer holds under adversarial conditions. Because the flaw is behavioral rather than signature-based, it may not show up in conventional automated scanning.

"Malcolm’s research on NatJack shows why effective security testing must challenge long-held design assumptions, not only for familiar software flaws,” said Mark Kuhr, co-founder and CTO of Synack. "That depth of human creativity is central to the Synack Red Team. We’re proud to support Malcolm’s research and help defenders understand and address the risk.”

There is no single patch for NatJack. Available fixes, including a Linux kernel patch (kernel 6.6.142 and higher) and a FreeBSD update (15.0 and higher), raise the difficulty of exploitation but do not close the underlying design gap. Synack expects remediation to unfold incrementally across vendors over an extended period, and recommends organizations prioritize encrypting traffic (including internally), segmenting untrusted workloads away from trusted ones, and enabling protections such as IP Source Guard in the interim. Full technical details and mitigation guidance are available in Synack's security research report on NatJack .

Malcolm Stagg's path to the Synack Red Team

Stagg joined the Synack Red Team in 2020 following his performance in DARPA’s Finding Exploits to Thwart Tampering hardware bug bounty. His research includes a Microsoft Remote Desktop Client RCE, CVE-2021-34535, and Google Chrome extension vulnerability CVE-2024-0333. Stagg discussed his NatJack research and path to the SRT on Synack's We're In podcast .

Malcolm Stagg, Researcher, Synack Red Team, Independent Researcher, SODIUM-24, LLC

Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure

Black Hat USA, Thursday, August 6, 10:15 a.m. PT (Oceanside D, Level 2)

Senior Content Marketing Manager

A photo accompanying this announcement is available at

Extracted Entities