CVE-2026-56181 is a high-severity vulnerability (CVSS 8.3) in Windows NAT used by Hyper-V. It is an origin-validation error that enables spoofing from an adjacent network. Affected releases include Windows 11 24H2 before 26100.8875, 25H2 before 26200.8875, 26H1 before 28000.2525, and Windows Server 2025 before 26100.33158. It is part of the NatJack attack class that manipulates NAT connection state.