NatJack Attack Class Exposes Vulnerabilities in NAT Implementations

NatJack Attack Class Exposes Vulnerabilities in NAT Implementations

First seen 6 Aug 2026, 23:23 UTC StreetinsiderManilatimesCsoonlinewww.globenewswire.comFeeds.4Sysops+1 89% similarity 69.0

Article Content

Browse articles
ThreatCluster

At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a new attack class exploiting design flaws in Network Address Translation (NAT) systems. All 32 tested NAT products across Windows, Linux, and macOS were found vulnerable to techniques including TCP connection hijacking and DNS response poisoning. Two CVEs have been assigned: CVE-2026-56181 for Windows NAT in Hyper-V and CVE-2026-63913 for the Linux netfilter conntrack subsystem. The vulnerabilities stem from a long-held assumption that devices sharing a NAT table can trust one another, which is no longer valid in adversarial conditions. Current patches raise exploitation difficulty but do not address the fundamental design flaw. Organizations are advised to encrypt traffic and segment untrusted workloads while awaiting further vendor updates.

Key Points: • NatJack exploits vulnerabilities in all tested NAT implementations across major OSs. • Two CVEs have been assigned, affecting both Windows and Linux NAT systems. • The attack class can hijack connections and poison DNS responses without victim action.

ThreatCluster AI How this analysis works

Timeline

2021-08-12
CVE-2021-34535 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2024-0333 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-56181 published
Vulnerability in Windows NAT allows unauthorized spoofing over adjacent networks.
www.globenewswire.com
2026-07-19
CVE-2026-63913 published
Linux netfilter conntrack vulnerability allows forced connection closure via invalid RST packets.
www.globenewswire.com
2026-08-06
NatJack research presented at Black Hat
Malcolm Stagg revealed the NatJack attack class, affecting 32 NAT products across multiple OSs.
Csoonline
2026-08-06
Synack announces NatJack findings
Research highlights the exploitation of long-held trust assumptions in NAT implementations.
Streetinsider

Community

Browse all →