Bottom line: NatJack is a newly presented attack class that, by manipulating NAT connection tables, enables TCP session hijacking, DNS spoofing, and NAT table exhaustion across multiple independent implementations.
Security researcher Malcolm Stagg presented a new attack class called NatJack at Black Hat USA 2026, which, by manipulating NAT connection states, can hijack active TCP sessions, spoof DNS responses, and exhaust NAT tables.
The attack class, named NatJack, targets the internal state management of Network Address Translation (NAT). According to Stagg, targeted manipulation of the NAT connection table not only allows the connection status of individual sessions to be influenced, but also enables active TCP sessions to be hijacked, DNS responses to be spoofed, and internally mapped ports to be exposed. In addition, a device’s NAT table can be exhausted through targeted requests, which can lead to denial-of-service effects.
According to the research, the affected behavior is not limited to a single implementation but was observed across multiple independently developed NAT implementations, including Windows. The originally linked source cuts off at this point, so there is no complete list of affected operating systems, router or firewall vendors, and no CVE assignment.
For CISOs, it is relevant that NAT has traditionally been regarded as a purely address-translation function rather than as a security-relevant control mechanism, even though many networks implicitly rely on NAT behavior as a protective layer. An attack class that exploits NAT state tables as an attack surface potentially affects perimeter devices, home and office routers, firewalls, and operating system NAT stacks alike — regardless of vendor.
As long as no detailed advisories, affected product versions, or patches are publicly available, security teams should monitor the Black Hat USA 2026 presentation and subsequent vendor notices, and additionally harden TCP session handling and DNS response validation at network boundaries, for example through DNSSEC validation and strict session timeout configurations on NAT gateways.
Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.