2026-08-10NOTABLEEvery evaluated NAT implementation fell to at least one primitive, and the Linux change is explicitly a partial mitigation rather than a fix
Windows NAT (Hyper-V, upstream-spoofing configuration), NatJack primitive; the August 2026 update adds ISN randomisation, shipped disabled by default and enabled only via a registry key
cve · CVE-2026-56179
Coverage
1
first 2026-08-10 → last 2026-08-24
Latest activity
2026-08-24
Every evaluated NAT implementation fell to at least one primitive, and the Linux change is explicitly a…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology, telco · regions: europe
Sources cited
5
4 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-56179, newest first. Check the date before acting on an older one.
- Identify environments where workloads of different trust levels share one NAT table (multi-tenant Hyper-V hosts, container nodes running mixed-trust workloads, shared cloud NAT gateways) and separate them; the Windows update closes its hijack path, but the Linux change is a partial mitigation and the other three primitives have no fix at all.2026-08-10CVE-2026-56181 +2
- On Hyper-V hosts using a NAT virtual switch, install the August 2026 Windows security update and then explicitly enable the ISN-randomisation mitigation for Windows NAT via the registry key Microsoft's advisory names; the update ships it disabled, so patched hosts remain exposed to the upstream-spoofing hijack until it is switched on.2026-08-10CVE-2026-56181 +2
Defender insights
What each entry about CVE-2026-56179 tells a defender to do, newest first.
Latest update
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 3 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Credential AccessAdversary-in-the-Middle
- CollectionAdversary-in-the-Middle
- ImpactNetwork Denial of Service: Direct Network Flood
Credential Access TA0006
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-10/natjack-nat-trust-assumption-attack-class-two-cves · ATT&CK page ↗
Collection TA0009
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-10/natjack-nat-trust-assumption-attack-class-two-cves · ATT&CK page ↗
Impact TA0040
T1498.001Network Denial of Service: Direct Network Flood×1
Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Direct Network Floods are when one or more systems are used to send a high-volume of network packets towards the targeted service's network. Almost any network protocol may be used for flooding. Stateless protocols such as UDP or ICMP are commonly used but stateful protocols such as TCP can be used as well.
Evidence: 2026-08-10/natjack-nat-trust-assumption-attack-class-two-cves · ATT&CK page ↗
Entries about Windows NAT (Hyper-V, upstream-spoofing configuration), NatJack primitive; the August 2026 update adds ISN randomisation, shipped disabled by default and enabled only via a registry key (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Linux kernel netfilter×1
- Microsoft Hyper-V×1
- Microsoft Windows NAT×1
- NatJack×1
- NatJack, Windows NAT origin-validation error allowing downstream-spoofing TCP session hijack, affecting Hyper-V; fixed in the July 2026 security update×1
- NatJack; Linux netfilter TCP conntrack state machine forced to CLOSE by an RST with an invalid sequence number, enabling downstream-spoofing TCP session hijack; fixed in 7.1 and stable/LTS backports×1
Where this entity is cited
Source distribution
- msrc.microsoft.com2 (40%)
- go.synack.com1 (20%)
- lore.kernel.org1 (20%)
- natjack.io1 (20%)
External references
All cited sources (5)
- msrc.microsoft.comprimaryMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179
- msrc.microsoft.comprimaryMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56181
- go.synack.comSynack Red Teamhttps://go.synack.com/security-research/natjack
- lore.kernel.orgLinux kernel CVE teamhttps://lore.kernel.org/linux-cve-announce/2026071946-CVE-2026-63913-9646@gregkh/T/#u
- natjack.ioMalcolm Stagghttps://natjack.io/