Vulnerabilities & Exploits

Shared NAT Is Not a Safe Isolation Boundary

Shared NAT breaks the old assumption that “same public IP” still means separation. NatJack shows an attacker on the same NAT boundary can manipulate connection tracking and take over live sessions, poison DNS replies, or knock connections offline without needing spoofed packets or local broadcast access.

Researchers disclosed the class at Black Hat and said 13 vendors were notified. They tested 32 products and configurations, and every one was vulnerable to some or all of the techniques, including affected Windows NAT and Linux kernel netfilter conntrack deployments.

2 sources · Aug 7

CVE-2026-56181

NVD KEV

CVSS 8.3 HIGH: origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform… Microsoft patch: 5099536.

Patch available KB5099536 Download →

CVE-2026-63913

NVD KEV

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-08-08

Every edition of this story: Shared NAT Is Not a Safe Isolation Boundary

More from today