NatJack Attacks Exploit NAT Table Flaws to Hijack TCP Sessions and Spoof DNS
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack…
CVE-2026-56181 is a high-severity vulnerability (CVSS 8.3) in Windows NAT used by Hyper-V. It is an origin-validation error that enables spoofing from…
CVE-2026-63913 is a high-severity vulnerability (CVSS 8.2) in Linux Netfilter conntrack. A crafted SYN followed by a reset packet with an invalid…
Synack, a security company, confirmed that researcher Malcolm Stagg tested NatJack techniques against dozens of real-world network infrastructure products from multiple vendors…
Windows NAT, used by Hyper-V, is affected by CVE-2026-56181, a high-severity vulnerability that allows spoofing from an adjacent network. The flaw is…
Linux Netfilter conntrack is affected by CVE-2026-63913, a high-severity vulnerability that allows an attacker to prematurely force NAT entries into a closed…
The NatJack attack class was presented at Black Hat USA 2026 by researcher Malcolm Stagg. The presentation detailed how NAT connection state…
Apple was notified of a macOS virtualization attack demonstrated as part of the NatJack research. Apple considered the behavior a known transport-layer…