• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

Critical Citrix Exploit Disrupt Dutch Hospitals and Government

Published on: September 28, 2026, 7:18 AM EDT
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 623 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
How VPNs Actually Work: Encryption, Tunnels, and What They Don’t Hide
Public WiFi Security Risks: What’s Real and What’s Overstated
What Is a VPS? How Virtual Private Servers Work and Who Actually Needs One
Robert A. Lee
Reviewed By
Robert A. Lee
Robert A. Lee
Senior Editor • 458 Articles
Robert A. Lee is a journalist at SQ Magazine who unpacks the fast-moving worlds of gaming and internet trends. He tracks everything from maj...
LATEST POSTS:
Average Attention Span Statistics 2026: The Cross-Domain Numbers
How AI Red Teaming Helps Identify Brand, Data and Digital Security Risks
Proxy-Backed Data Feeds That Don’t Break: A Practical Pattern for SEO and Price Tracking
Citrix NetScaler Zero-Days Exploited Dutch Systems Shut
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Citrix confirmed on 27th September 2026 that attackers exploited two NetScaler zero-days before any fix existed, and one of them needs no login. Dutch hospitals and the national government had already cut remote access as a precaution.

The Brief

  • Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and NetScaler Gateway and shipped fixed builds.
  • CVE-2026-88771 lets an attacker run commands on the appliance without logging in, and default setups are exposed.
  • Two Dutch hospitals, Amphia and Elisabeth-TweeSteden, shut off patient access to online records while care continued.
  • The Dutch government disconnected all its Citrix environments from the internet, so staff working from home could not log in.
  • CISA added both flaws to its exploited-vulnerabilities catalog and gave US federal agencies until 30th September, 2026 to act.

What Happened?

Hospitals, banks and other large organizations use NetScaler to spread traffic across servers. Many also run it as the front door for remote logins. Citrix security bulletin CTX697096 covers eight vulnerabilities in total. Citrix says upgrading is the only fix.

“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said in the bulletin.

CVE-2026-88771 is an improper input validation bug that lets an unauthenticated attacker execute arbitrary commands over the network. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service. It needs DTLS (Datagram Transport Layer Security), which is on by default for VPN virtual servers. The other six flaws, CVE-2026-88773 through CVE-2026-88778, cover request smuggling, policy bypass, more memory overflows and TCP sequence-number prediction.

CVE-2026-88771 – the loaded Citrix footgun went off again, and the screaming noise is back in our ear.

You knew it was coming – enjoy the latest watchTowr Labs blogpost.https://t.co/cKN1oqLwpK

— watchTowr (@watchtowrcyber) September 28, 2026

Citrix lists these fixed builds:

  • NetScaler ADC and Gateway 14.1-73.37 and later
  • NetScaler ADC and Gateway 13.1-64.23 and later
  • NetScaler ADC FIPS 14.1-73.37 FIPS and later
  • NetScaler ADC FIPS and NDcPP 13.1-37.279

Secure Private Access Hybrid deployments on NetScaler need the same upgrade, and CVE-2026-88778 also calls for TCP configuration changes. The bulletin applies only to self-managed appliances, since Cloud Software Group, Citrix’s owner, has already updated its managed cloud services and Adaptive Authentication.

Dutch hospitals and ministries pulled the plug first

Z-CERT, the Dutch healthcare sector’s cybersecurity center, warned institutions about critical vulnerabilities and recommended steps that included shutting systems down. According to Dutch public broadcaster NOS, that hit Amphia Hospital in Breda and Elisabeth-TweeSteden Hospital in Tilburg and Waalwijk. Doctors kept access to records, but patients lost their online view. Frisius MC in Leeuwarden switched off a few systems without touching patient care and has since recovered.

The Ministry of the Interior said Citrix had reported serious risks, and the national government took every Citrix environment off the internet. Civil servants at home could not log in, some Citrix-hosted apps stopped working, and only office desktops kept reliable access. That shows how much remote work cybersecurity hangs on a single gateway.

The Netherlands has been here before, when a NetScaler flaw took the Dutch judicial system offline in mid-2025. A no-login bug with no workaround leaves one stopgap: close the door and lock out the people it serves. NCSC-NL (the Netherlands’ National Cyber Security Centre) now says the vulnerabilities have been resolved.

Admins need to hunt before they patch

CISA’s catalog entry for CVE-2026-88771 requires forensic triage under Binding Operational Directive 26-04, which binds US federal civilian agencies. CISA’s alert also urges organizations to check for compromise before patching, using indicators Citrix published through NetScaler Console. Rescana reports post-exploitation webshells, credential theft and lateral movement.

Teams on an affected build should run those indicators first, then upgrade and apply the CVE-2026-88778 TCP changes. Resetting credentials that passed through the appliance helps reduce risk if theft already happened. Where an upgrade must wait, Rescana advises cutting the appliance off from the internet and watching it closely.

The record still has gaps. No Dutch hospital or ministry has said attackers got in, and no group has been named. Nobody has said how long exploitation ran before disclosure. Rescana notes that earlier NetScaler flaws drew both ransomware crews and state-backed espionage groups.

The next hard marker is 09/30/2026, the federal deadline for patching and triage. In the Netherlands, the clearer signal comes when a civil servant working from home can log in again.

This article has been reviewed and fact-checked by Robert A. Lee. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity

References

  • NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096)
  • Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Servicenow Cve Vulnerability Patches
Cybersecurity

ServiceNow Security Alert: Patch These Critical Flaws

Microsoft Windows Deployment Service Deprecation
Technology

Microsoft Will Deprecate Windows Deployment Services After Server 2025

Microsoft Copilot Complete Overhaul Adds Code and Autopilot
Artificial Intelligence

Microsoft Copilot Complete Overhaul Adds Code and Autopilot

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

How AI Red Teaming Helps Identify Brand, Data and Digital Security Risks
How VPNs Actually Work: Encryption, Tunnels, and What They Don’t Hide
Public WiFi Security Risks: What’s Real and What’s Overstated

Table of Contents

  • The Brief
  • What Happened?
  • Dutch hospitals and ministries pulled the plug first
  • Admins need to hunt before they patch

Weekly stats quiz Week 40

How much of a tech geek are you?

5 fast questions from this week's verified industry data. About a minute.

Play the quiz New every Monday

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • The Tech Index
  • The Threat Index
  • Social Media Attention Span Stats
  • Instagram Followers Stats
  • Google Usage Stats
  • LLM Hallucination Stats
  • Gen Z Social Media Stats
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cryptocurrency
Internet
Average Attention Span Statistics The Cross-Domain Numbers
Average Attention Span Statistics 2026: The Cross-Domain Numbers
How Many Videos Are on YouTube Statistics
How Many Videos Are on YouTube Statistics 2026: Key Data
How Many People Work at WhatsApp
How Many People Work at WhatsApp 2026: Employee Count and History
Spotify Listening Statistics
Spotify Listening Statistics 2026: Average Listening Time
How Many Subscribers Does MrBeast Have
How Many Subscribers Does MrBeast Have in 2026? Channel Growth Statistics
WhatsApp Business Statistics
WhatsApp Business Statistics 2026: Real Market Insights
Technology
Aptoide Statistics 2026: Downloads, Users and App Store Share
Aptoide Statistics 2026: Downloads, Users and App Store Share
AppsFlyer Statistics Customers Revenue and Market Position
AppsFlyer Statistics 2026: Customers, Revenue and Market Position
How Many iPhones Has Apple Sold
How Many iPhones Has Apple Sold in 2026? Units Sold by Year
How Many Employees Does Amazon Have
How Many Employees Does Amazon Have 2026: Workforce Growth
Netflix vs. Hulu Statistics
Netflix vs Hulu Statistics 2026: Viewer Growth Data
TripAdvisor Statistics
TripAdvisor Statistics 2026: Revenue, Reviews, Viator and TheFork Data
Artificial Intelligence
AI Search Engine Statistics Usage Market Share and Adoption
AI Search Engine Statistics 2026: Usage, Market Share and Adoption
AI Music Statistics
AI Music Statistics 2026: Generation, Adoption and Industry Impact
AI Coding Statistics
AI Coding Statistics 2026: Adoption, Productivity and Market Data
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
Gaming
Gaming Statistics
Gaming Statistics 2026: Market Size, Players, Revenue, and Platforms
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Cryptocurrency
How Many Bitcoins Are There
How Many Bitcoins Are There in 2026? Supply, Mined and Remaining Statistics
Stablecoin Usage Statistics
Stablecoin Usage Statistics 2026: Explosive Growth
Cryptocurrency Adoption Statistics
Cryptocurrency Adoption Statistics 2026: Shocking Trends Now
Coinbase Wallet Statistics
Coinbase Wallet Statistics 2026: Users, Security
Dogecoin Statistics
Dogecoin Statistics 2026: Annual Supply Increase, Circulating Supply, and Inflation Rate
BONK Coin Statistics
BONK Coin Statistics 2026: Risk, Reward, and ROI
Categories
  • Artificial Intelligence
  • Cybersecurity
  • Technology
  • Internet
  • Cryptocurrency
Artificial Intelligence
Microsoft Copilot Complete Overhaul Adds Code and Autopilot
Microsoft Copilot Complete Overhaul Adds Code and Autopilot
Gemini Call For Me Feature Pixel 11
Google Gemini Can Now Call Businesses for Pixel 11 Owners
Adobe Creative Tools Gemini Claude Addition
Adobe Unlocks New Creative Tools in Gemini and Claude
Youtube Music Ask Music Ai Feature
YouTube Music Adds Smart AI Features for Songs and Podcasts
OpenAI Launches GPT-6 Sol and Luna at Half the API Price
OpenAI Launches GPT-6 Sol and Luna at Half the API Price
Claude Opus 5 5 Launched
Claude Opus 5.5 Debuts With Powerful Cyber Defenses
Cybersecurity
Citrix NetScaler Zero-Days Exploited Dutch Systems Shut
Critical Citrix Exploit Disrupt Dutch Hospitals and Government
Servicenow Cve Vulnerability Patches
ServiceNow Security Alert: Patch These Critical Flaws
Manus Ai Prompt Injection
Manus AI Agent Exposed by Prompt-Injection Bug
Arista Velocloud Flaw Patched
Arista VeloCloud Flaw Hits CVSS 10.0: Patch Now
Microsoft Takes Down Eviltokens Ai Phishing Service
Microsoft Takes Down EvilTokens AI Phishing Service
Microsoft Patches Azure Ai Foundry Cvss 10 Flaw Featured 1
Microsoft Patches 18 Azure and Copilot Security Vulnerabilities
Technology
Microsoft Windows Deployment Service Deprecation
Microsoft Will Deprecate Windows Deployment Services After Server 2025
Youtube Custom Feeds With Gemini Ai
YouTube’s AI Feed Builder Changes Video Discovery
Iphone 18 Pro Face Id Bug Reboot Crash
New iPhone 18 Pro Bug Makes Face ID Crash and Reboot
Googlebook With Gemini Ai Launched
Googlebook’s Bold Laptop Launch Starts at $899 in the US
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
New Samsung Patent Reveals Galaxy Watch Glucose Tracking
Microsoft Kb5002914 Breaks Excel Copypaste
Microsoft Confirms KB5002914 Breaks Excel Copy and Paste
Internet
Meta Launched Meta One Subscription
Meta One Bundles Instagram, Facebook, WhatsApp Into One AI Subscription
Apple Wallet Ids Launch In Oklahoma
Apple Wallet IDs Launch in Oklahoma in Major Expansion
Meta to Pay 18 Billion in Landmark Teen Safety Deal
Meta to Pay $18 Billion in Landmark Teen Safety Deal
Whatsapp Brings Passkeys 2fa
WhatsApp Hits 1 Billion Passkey Users, Adds 2FA Passwords
Apple Eu App Store Fee Reduction
Apple Sets New EU App Store Fees, Effective October 1
Github Outage Aug 2026
GitHub Down: Outage Hits Thousands of Users Worldwide
Cryptocurrency
Sonic Labs Launch Ussd Stablecoin
Sonic Launches USSD Stablecoin Backed by US Treasuries
Bhutan Moves 12m In Bitcoins
Bhutan Moves $12 Million in Bitcoin from Primary Wallets
Curve Finance Accuses Pancakeswap For Code Stealing
Curve Accuses PancakeSwap of Copying StableSwap Code
Strike Receives Bitlicense In New York
Strike Gets New York BitLicense for Bitcoin Financial Services
Scotiabank Multi Crypto Etf 3iqlogos
Scotiabank Launches Multi Crypto ETF With 3iQ in Canada
Nyse Parent Invests In Okx Crypto Exchange
ICE Invests in OKX to Bridge Crypto and Traditional Finance
Newsletter

Too much tech noise?

We respect your time. One high-signal briefing a week: tech, AI, and security. Nothing else.

Newsletter

The SQ Briefing

We track tech, AI, and security 24/7. You get a 5-minute weekly summary.