# NatJack: Researchers Weaponize NAT's Trusted-Neighbor Assumption to Hijack TCP and Spoof DNS
## The Threat
NAT was never designed with adversarial tenants in mind. That implicit assumption — that hosts behind the same network address translator won't interfere with each other's connection state — is exactly what security researcher Malcolm Stagg spent months systematically dismantling. The result, presented at Black Hat USA 2026, is NatJack: a class of attacks that exploit NAT connection-tracking logic to hijack live TCP sessions, intercept and forge DNS responses, enumerate externally mapped ports, and brick NAT tables with spoofed flows until legitimate clients can't connect at all.
What makes NatJack alarming isn't the novelty of any single technique — NAT-state manipulation research has a paper trail going back years. It's the breadth. Stagg tested across dozens of real-world network infrastructure products from multiple vendors and found the vulnerable behavior in independently developed implementations, including both Windows and Linux. When the same fundamental design flaw surfaces in products that share no code, that's not a bug — it's an architecture problem.
The attack surface is tighter than a remote vulnerability: an attacker needs privileged access to a host behind the same NAT as their target. But in cloud environments, shared VPCs, datacenter multitenant segments, and enterprise networks where guest Wi-Fi or contractor machines share NAT infrastructure with production systems, that constraint is considerably less protective than it sounds.
## Severity and Impact
| CVE | CVSS Score | Affected Component | Attack Vector | Attack Complexity | Privileges Required | CWE |
|-----|------------|-------------------|---------------|-------------------|---------------------|-----|
| CVE-2026-56181 | 8.3 | Windows NAT (Hyper-V) | Adjacent Network | Low | Low | CWE-346 (Origin Validation Error) |
| CVE-2026-63913 | 8.2 | Linux Netfilter conntrack | Adjacent Network | Low | Low | CWE-354 (Improper Validation of Integrity Check Value) |
The two CVEs address implementation-specific flaws, but the broader NatJack technique class has no single assigned CVE and no universal patch. The Linux kernel fix tightens the conntrack logic but, per Stagg's own assessment, only raises attack complexity on the downstream spoofing path — it doesn't eliminate it.
## Affected Products
Windows
Linux Kernel (Netfilter conntrack)
- 5.10.259
- 5.15.210
- 6.1.176
- 6.6.143
- 6.12.93
- 6.18.35
- 7.0.12
- 7.1
Broader ecosystem: Stagg tested against dozens of network infrastructure products across multiple vendors. No public product-by-product matrix has been released, but the NDSS 2024 research this work builds on found 52 of 67 tested routers susceptible to related NAT-mapping manipulation. Assume any NAT implementation that doesn't explicitly validate session ownership is potentially in scope.
## Mitigations
Patch immediately where patches exist:
Architectural controls (for the unpatched attack class):
No patch addresses the full technique class. Defense-in-depth — particularly encryption everywhere and strict network segmentation — is the operational posture until vendor implementations are individually hardened.
## References
---
## HackWire Analysis
NatJack lands at an uncomfortable moment for enterprise security teams already stretched thin on network hygiene. The research exposes something most organizations have quietly assumed was safe: that internal NAT boundaries carry meaningful security weight. They don't, and they never really did — but NatJack is the first research to make that failure exploitable across a wide, heterogeneous product landscape at Black Hat scale.
The comparison to the NDSS 2024 findings is instructive. That paper tested 67 routers and found 52 of them susceptible to TCP hijacking via NAT manipulation, producing ten CVEs. NatJack extends that work into a full technique family — DNS spoofing, port disclosure, DoS via table exhaustion — and targets the same root assumption across OS-level NAT stacks, not just routers. The pattern is clear: NAT session-ownership validation has been an afterthought across the entire industry, from commodity routers to enterprise hypervisors.
For cloud and multitenant environments, this is the most acute exposure. Any architecture where customer VMs, CI/CD pipelines, or third-party workloads share a NAT boundary with control-plane systems needs an immediate re-evaluation. The "adjacent network" attack vector sounds scoped — it's not, in practice, when shared VPCs and flat datacenter subnets are the norm.
The TCP hijacking and DNS spoofing paths are the two that should keep defenders up at night. Both can be used to intercept credentials or plant malicious responses without triggering obvious anomalies. The DoS path is loud and easier to detect; the exfiltration paths are not. Organizations running Hyper-V on Windows Server 2025 should treat the patch as P0. Everyone else should start mapping which networks share NAT state with anything they care about — before someone else does it for them.
— HackWire Editorial
---
## Related Coverage