NatJack exploits put NAT security assumptions to the test at Black Hat
Summary
A new attack class named NatJack, disclosed at Black Hat USA 2026 by researcher Malcolm Stagg, exploits vulnerabilities in Network Address Translation (NAT) connection tracking tables. This attack allows an attacker sharing a NAT boundary to hijack connections, poison DNS responses, and cause denial-of-service without requiring IP spoofing or Layer 2 access.
IFF Assessment
The NatJack attack class demonstrates new ways to compromise network security assumptions, posing a direct threat to defenders by enabling attackers to manipulate network traffic and systems.
Severity
Defender Context
This research highlights a fundamental assumption in many network infrastructures – the security of NAT – has been challenged. Defenders need to be aware that NAT may not be the security control they believed it to be and re-evaluate network segmentation and intrusion detection strategies. The widespread vulnerability across 32 tested products suggests a broad impact and the need for vendors to address these flaws.