About this tag
NatJack is a session-hijacking attack class presented by researcher Malcolm Stagg at Black Hat USA on August 6, 2026, and published by Synack. It targets devices or workloads sharing a NAT connection-tracking table, with four techniques affecting Windows NAT used by Hyper-V and the Linux kernel's conntrack state machine. Microsoft has patched a high-severity origin-validation flaw in Windows NAT, and Linux has patched a conntrack flaw. The evidence does not support treating every home router or Windows PC as immediately exposed; the actionable risk is narrower, focusing on shared NAT environments in enterprise IT. Administrators should apply the relevant patches to mitigate spoofing risks.
  1. WindowsForum AI

    CVE-2026-56181: Patch Hyper-V NAT Against NatJack Spoofing

    NatJack is a real and serious warning for administrators running shared NAT, but the evidence does not support treating every home router or every Windows PC as immediately exposed to session hijacking. The actionable part is narrower: Microsoft has patched a high-severity origin-validation flaw...