Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS

NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS

Posted on August 7, 2026 By CWS

Malcolm Stagg, a security researcher, has unveiled a new type of attack named NatJack, which targets network address translation (NAT) systems to hijack ongoing TCP sessions, falsify DNS responses, reveal mapped ports, and overwhelm NAT tables. This groundbreaking research was showcased at the Black Hat USA 2026 conference, revealing vulnerabilities in both Windows and Linux systems.

Understanding the NatJack Exploit

The NatJack attack exploits flaws in NAT implementations, affecting both Windows and Linux platforms. Two critical vulnerabilities have been identified: CVE-2026-56181 in Windows NAT utilized by Hyper-V with a CVSS score of 8.3, and CVE-2026-63913 in Linux Netfilter conntrack with a score of 8.2. These vulnerabilities demonstrate how attackers can manipulate NAT connection states, leading to severe security implications.

To execute a NatJack attack, an adversary typically needs privileged access to a system sharing the same NAT as the target. This necessitates robust separation of untrusted and trusted workloads within shared NAT environments to prevent exploitation.

Mitigation Strategies and Current Solutions

There is no comprehensive patch available for the NatJack attack class. Organizations are advised to apply the latest updates for Windows and Linux systems and to encrypt internal network communications. Implementing Internet Protocol (IP) Source Guard can further mitigate potential threats.

The NatJack research highlights a fundamental assumption in many NAT implementations: that systems behind the same NAT do not interfere with each other’s connection states. By exploiting this assumption, an attacker can manipulate connection-tracking entries of other systems, posing significant risks to network security.

Technical Insights and Industry Response

The research outlines several attack vectors, including redirecting traffic from active TCP connections by altering NAT mappings and intercepting DNS requests to send forged responses. Additional techniques involve disclosing externally mapped ports or overloading NAT tables, preventing legitimate client connections.

Synack’s testing of these techniques across various network infrastructure products from different vendors demonstrated proof-of-concept exploitation in controlled environments. However, as of August 7, 2026, there is no public evidence indicating these techniques have been used in real-world attacks.

Linux vulnerabilities are addressed in kernel updates, with fixed versions including 5.10.259 and newer. Although these updates mitigate certain aspects of the attack, they do not completely eliminate the threat. Similarly, Microsoft’s updates address origin-validation errors in Windows, impacting several releases.

NatJack builds on prior research into NAT-state manipulation, with past studies revealing a significant number of routers susceptible to similar attacks, leading to multiple CVE assignments.

As network security continues to evolve, understanding and addressing vulnerabilities like those exploited by NatJack remain crucial for safeguarding systems against sophisticated threats.

The Hacker News Tags:Black Hat 2026, CVE, DNS spoofing, Linux, NAT vulnerabilities, NatJack, network security, SODIUM-24, Stagg, TCP hijacking, Windows

Post navigation

Previous Post: Critical Vulnerabilities in Enterprise Java Platforms Uncovered

Related Posts

Evolving Enterprise Defense to Secure the Modern AI Supply Chain Evolving Enterprise Defense to Secure the Modern AI Supply Chain The Hacker News
OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity The Hacker News
Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure The Hacker News
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands The Hacker News
Understanding MFA Prompt Bombing: Risks and Solutions Understanding MFA Prompt Bombing: Risks and Solutions The Hacker News
Citrix Releases Patches for NetScaler Vulnerabilities Citrix Releases Patches for NetScaler Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS
  • Critical Vulnerabilities in Enterprise Java Platforms Uncovered
  • OpenAI Unveils GPT-5.6 with Unlimited Chat Access
  • 3.8 Million Affected by Major Unlimited Technology Systems Breach
  • TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NatJack Exploits NAT Vulnerabilities to Hijack TCP and DNS
  • Critical Vulnerabilities in Enterprise Java Platforms Uncovered
  • OpenAI Unveils GPT-5.6 with Unlimited Chat Access
  • 3.8 Million Affected by Major Unlimited Technology Systems Breach
  • TeamPCP’s Cyber Attacks Trace Back to 2020, Supply Chain Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark