Skip to content
NatJack Attack Class Exposes Vulnerabilities in NAT Implementations

NatJack Attack Class Exposes Vulnerabilities in NAT Implementations

First seen 6 Aug 2026, 23:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 7, 2026 at 23:08 UTC
  • NatJack exploits vulnerabilities in all tested NAT implementations across major OSs.
  • Two CVEs have been assigned, affecting both Windows and Linux NAT systems.
  • The attack class can hijack connections and poison DNS responses without victim action.

At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a new attack class exploiting design flaws in Network Address Translation (NAT) systems. All 32 tested NAT products across Windows, Linux, and macOS were found vulnerable to techniques including TCP connection hijacking and DNS response poisoning. Two CVEs have been assigned: CVE-2026-56181 for Windows NAT in Hyper-V and CVE-2026-63913 for the Linux netfilter conntrack subsystem. The vulnerabilities stem from a long-held assumption that devices sharing a NAT table can trust one another, which is no longer valid in adversarial conditions. Current patches raise exploitation difficulty but do not address the fundamental design flaw. Organizations are advised to encrypt traffic and segment untrusted workloads while awaiting further vendor updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2021-08-12
CVE-2021-34535 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2024-0333 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-56181 published
Vulnerability in Windows NAT allows unauthorized spoofing over adjacent networks.
www.globenewswire.com
2026-07-19
CVE-2026-63913 published
Linux netfilter conntrack vulnerability allows forced connection closure via invalid RST packets.
www.globenewswire.com
2026-08-06
NatJack research presented at Black Hat
Malcolm Stagg revealed the NatJack attack class, affecting 32 NAT products across multiple OSs.
Csoonline
2026-08-06
Synack announces NatJack findings
Research highlights the exploitation of long-held trust assumptions in NAT implementations.
Streetinsider

More articles in this cluster (15)

Following this threat?

Track CVE-2021-34535 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed