NatJack exploits put NAT security assumptions to the test at Black Hat
For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.
The short version
- The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was).
- At Black Hat USA 2026 , researcher Malcolm Stagg , an independent researcher and Synack Red Team member, disclosed NatJack, an attack class that manipulates the NAT connection tracking table.
- An attacker sharing a NAT boundary with a victim can hijack active connections, poison DNS responses, and force denial of service , without the IP spoofing or broadcast domain access older Layer 2 attacks required.
What happened
Thirteen vendors were notified, and testing covered 32 products and configurations across 95 reports. Every tested implementation was vulnerable to some or all of the NatJack techniques.
Why it matters
Stagg didn’t intentionally set out to find flaws in NAT, but he found them.
Summary by Nerd News Network. Read the full article at Network World via the links above and below.
