New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
ResearchWindows NATLinux Netfilter conntrackOur summary
Security researcher Malcolm Stagg has uncovered a novel threat known as NatJack, which abuses weaknesses in Network Address Translation (NAT) mechanisms to hijack active TCP sessions, spoof DNS responses, and exhaust NAT resources. The technique was presented at Black Hat USA 2026 and affects both Windows NAT via Hyper-V and Linux Netfilter conntrack. Two specific vulnerabilities—CVE-2026-56181 (Windows, CVSS 8.3) and CVE-2026-63913 (Linux, CVSS 8.2)—have been identified, though the broader attack concept relies on design assumptions rather than a single flaw. Mitigations include isolating untrusted systems from shared NAT environments and applying available OS updates.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.