A new class of attacks, dubbed NatJack, has been disclosed by security researcher Malcolm Stagg, capable of manipulating network address translation (NAT) connection states to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The research, presented at Black Hat USA 2026, found the attack affects independently developed implementations, including Windows and Linux, with further coverage provided by The Hacker News.NatJack exploits a fundamental assumption in many NAT implementations: that systems behind the same NAT will not interfere with each other's connection states. Attackers with privileged access to a system sharing NAT with a victim can manipulate connection-tracking entries. This can lead to traffic redirection by replacing NAT mappings, DNS spoofing by intercepting and forging DNS responses, disclosure of externally mapped ports, or exhaustion of NAT tables, preventing new connections. Two specific vulnerabilities have received CVEs: CVE-2026-56181 (CVSS 8.3) in Windows NAT for Hyper-V and CVE-2026-63913 (CVSS 8.2) in Linux Netfilter conntrack.Mitigation strategies include applying available OS updates, encrypting internal network traffic, and implementing IP Source Guard. While specific patches address the CVEs, they only mitigate the broader attack class, increasing complexity rather than eliminating the threat.Source: The Hacker News
Network Security
New NatJack attack class exploits NAT vulnerabilities to hijack TCP sessions
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
