CVE-2026-56181
CVSS 8.3 HIGH: origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform… Microsoft patch: 5099536.
Patch available KB5099536 Download →
Vulnerabilities · 52 days ago
Shared NAT breaks the old assumption that “same public IP” still means separation. NatJack shows an attacker on the same NAT boundary can manipulate connection tracking and take over live sessions, poison DNS replies, or knock connections offline without needing spoofed packets or local broadcast access.
Researchers disclosed the class at Black Hat and said 13 vendors were notified. They tested 32 products and configurations, and every one was vulnerable to some or all of the techniques, including affected Windows NAT and Linux kernel netfilter conntrack deployments.
CVSS 8.3 HIGH: origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform… Microsoft patch: 5099536.
Patch available KB5099536 Download →
2 sources covering this story
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
NatJack abuses NAT state to hijack TCP sessions and spoof DNS responses; Windows and Linux flaws are tracked under two CVEs.
NatJack exploits put NAT security assumptions to the test at Black Hat
NatJack attack class exposes design flaw across decades of network infrastructure.
Part of the PlainSec briefing for 2026-08-08