Manilatimes
NatJack Attack Class Exposes Vulnerabilities in NAT Implementations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a new attack class exploiting design flaws in Network Address Translation (NAT) systems. All 32 tested NAT products across Windows, Linux, and macOS were found vulnerable to techniques including TCP connection hijacking and DNS response poisoning. Two CVEs have been assigned: CVE-2026-56181 for Windows NAT in Hyper-V and CVE-2026-63913 for the Linux netfilter conntrack subsystem. The vulnerabilities stem from a long-held assumption that devices sharing a NAT table can trust one another, which is no longer valid in adversarial conditions. Current patches raise exploitation difficulty but do not address the fundamental design flaw. Organizations are advised to encrypt traffic and segment untrusted workloads while awaiting further vendor updates.
Key Points: • NatJack exploits vulnerabilities in all tested NAT implementations across major OSs. • Two CVEs have been assigned, affecting both Windows and Linux NAT systems. • The attack class can hijack connections and poison DNS responses without victim action.