Security researcher Malcolm Stagg disclosed NatJack, a new attack class that abuses Network Address Translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, reveal mapped ports, and exhaust NAT tables on affected infrastructure devices. The research, presented at Black Hat USA 2026 and detailed at natjack.io, describes weaknesses observed across multiple independently developed NAT implementations rather than a single vendor-specific flaw.
Implementation-specific issues have been tracked as CVE-2026-56181 for Windows NAT for Hyper-V and CVE-2026-63913 for Linux Netfilter conntrack. The attack generally requires privileged access to a host behind the same NAT as the victim, making shared NAT environments a key risk area. Recommended mitigations include separating trusted and untrusted workloads that share NAT infrastructure, applying available Windows and Linux patches, encrypting internal traffic, and using IP Source Guard where possible; no single patch addresses the broader NatJack attack class, and there was no public evidence of in-the-wild exploitation at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Security researcher Malcolm Stagg disclosed a new attack class called NatJack and presented the research at Black Hat USA 2026. The work showed that manipulating NAT connection state can enable TCP session hijacking, DNS spoofing, mapped-port disclosure, and NAT table exhaustion across multiple NAT implementations.
An implementation-specific NatJack-related issue in Linux Netfilter conntrack was tracked as CVE-2026-63913. The kernel.org CNA record said crafted packets could prematurely force an active NAT entry into a closed state because the conntrack logic failed to validate packet direction.
An implementation-specific NatJack-related issue in Windows NAT for Hyper-V was tracked as CVE-2026-56181. Microsoft's CNA record described it as an origin-validation error that could enable spoofing from an adjacent network.
Fixed Linux stable releases for CVE-2026-63913 were made available, including versions 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12, and 7.1. Stagg said the kernel fix corrects the code flaw but only raises the complexity of the broader downstream-spoofing technique.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcenatjack.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.