---
title: "Critical Citrix Exploit Disrupt Dutch Hospitals and Government"
date: 2026-09-28
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/citrix-netscaler-zero-days-exploited-dutch-systems-shut.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Critical Citrix Exploit Disrupt Dutch Hospitals and Government

Citrix confirmed on 27th September 2026 that attackers exploited two NetScaler zero-days before any fix existed, and one of them needs no login. Dutch hospitals and the national government had already cut remote access as a precaution.

## The Brief

- Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and NetScaler Gateway and shipped fixed builds.
- CVE-2026-88771 lets an attacker run commands on the appliance without logging in, and default setups are exposed.
- Two Dutch hospitals, Amphia and Elisabeth-TweeSteden, shut off patient access to online records while care continued.
- The Dutch government disconnected all its Citrix environments from the internet, so staff working from home could not log in.
- CISA added both flaws to its exploited-vulnerabilities catalog and gave US federal agencies until 30th September, 2026 to act.

## What Happened?

Hospitals, banks and other large organizations use NetScaler to spread traffic across servers. Many also run it as the front door for remote logins. [Citrix security bulletin CTX697096](https://support.citrix.com/external/article/CTX697096) covers eight vulnerabilities in total. Citrix says upgrading is the only fix.

**“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,”** Citrix said in the bulletin.

CVE-2026-88771 is an improper input validation bug that lets an unauthenticated attacker execute arbitrary commands over the network. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It needs DTLS (**Datagram Transport Layer Security**), which is on by default for VPN virtual servers. The other six flaws, CVE-2026-88773 through CVE-2026-88778, cover request smuggling, policy bypass, more memory overflows and TCP sequence-number prediction.

> CVE-2026-88771 – the loaded Citrix footgun went off again, and the screaming noise is back in our ear.  
>   
> You knew it was coming – enjoy the latest watchTowr Labs blogpost.<https://t.co/cKN1oqLwpK>
> 
> — watchTowr (@watchtowrcyber) [September 28, 2026](https://x.com/watchtowrcyber/status/2104525580670472453?ref_src=twsrc%5Etfw)

 Citrix lists these fixed builds:

- **NetScaler ADC and Gateway 14.1-73.37 and later**
- **NetScaler ADC and Gateway 13.1-64.23 and later**
- **NetScaler ADC FIPS 14.1-73.37 FIPS and later**
- **NetScaler ADC FIPS and NDcPP 13.1-37.279**

Secure Private Access Hybrid deployments on NetScaler need the same upgrade, and CVE-2026-88778 also calls for TCP configuration changes. The bulletin applies only to self-managed appliances, since Cloud Software Group, Citrix’s owner, has already updated its managed cloud services and Adaptive Authentication.

## Dutch hospitals and ministries pulled the plug first

**Z-CERT**, the Dutch healthcare sector’s cybersecurity center, warned institutions about critical vulnerabilities and recommended steps that included shutting systems down. According to Dutch public broadcaster NOS, that hit **Amphia Hospital** in Breda and **Elisabeth-TweeSteden Hospital** in Tilburg and Waalwijk. Doctors kept access to records, but patients lost their online view. Frisius MC in Leeuwarden switched off a few systems without touching patient care and has since recovered.

The Ministry of the Interior said Citrix had reported serious risks, and the national government took every Citrix environment off the internet. Civil servants at home could not log in, some Citrix-hosted apps stopped working, and only office desktops kept reliable access. That shows how much [remote work cybersecurity](https://sqmagazine.co.uk/remote-work-cybersecurity-statistics/) hangs on a single gateway.

The Netherlands has been here before, when a NetScaler flaw took the Dutch judicial system offline in mid-2025. A no-login bug with no workaround leaves one stopgap: close the door and lock out the people it serves. NCSC-NL (the **Netherlands’ National Cyber Security Centre**) now says the vulnerabilities have been resolved.

## Admins need to hunt before they patch

[CISA’s catalog entry for CVE-2026-88771](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) requires forensic triage under Binding Operational Directive 26-04, which binds US federal civilian agencies. CISA’s alert also urges organizations to check for compromise before patching, using indicators Citrix published through NetScaler Console. Rescana reports post-exploitation webshells, credential theft and lateral movement.

Teams on an affected build should run those indicators first, then upgrade and apply the CVE-2026-88778 TCP changes. Resetting credentials that passed through the appliance helps reduce risk if theft already happened. Where an upgrade must wait, Rescana advises cutting the appliance off from the internet and watching it closely.

The record still has gaps. No Dutch hospital or ministry has said attackers got in, and no group has been named. Nobody has said how long exploitation ran before disclosure. Rescana notes that earlier NetScaler flaws drew both ransomware crews and [state-backed espionage groups](https://sqmagazine.co.uk/cyber-warfare-statistics/).

The next hard marker is 09/30/2026, the federal deadline for patching and triage. In the Netherlands, the clearer signal comes when a civil servant working from home can log in again.