Citrix flaw puts healthcare and home working under pressure
Dutch cyber security services warn of active exploitation of critical vulnerabilities in NetScaler systems.
The National Cyber Security Centre and Z-CERT are warning of eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Citrix says two of them are already being actively exploited; organisations should install security updates and take into account possible earlier exploitation.
NetScaler systems are used as gateways to business and healthcare applications, including for remote connections. On Sunday, Citrix published a security advisory on eight vulnerabilities in customer-managed versions of NetScaler ADC and NetScaler Gateway. The issues affect, among others, certain versions in the 13.1 and 14.1 series.
The two most serious vulnerabilities are CVE-2026-88771 and CVE-2026-88772. The NCSC gives both a CVSS score of 9.5 on a scale of 10. According to the security advisories, the first vulnerability could allow remote code execution without prior authentication. Under certain circumstances, the second could lead to code execution or a service disruption.
Citrix says exploitation of both vulnerabilities has been observed on systems where the security updates had not yet been installed. The company advises customers to move to versions containing the security updates as soon as possible. For cloud services managed by Citrix, the supplier says it is carrying out the updates itself.
Z-CERT has warned participating healthcare organisations as a precaution. The organisation advises institutions to temporarily disable vulnerable systems or monitor them more closely, depending on their situation. This could affect external access to healthcare applications and patient portals, but public sources do not provide a complete overview of institutions that have actually reported disruptions.
The NCSC warns that installing security updates does not rule out the possibility that a system was compromised earlier. For systems that were exposed to the internet before the update, the centre therefore also advises investigating possible previous access. Relevant log files and a memory dump can be secured before installing the update for forensic investigation.
The warning also affects government organisations and companies that use NetScaler for VPN or home-working connections. The precise consequences vary by configuration. This is therefore not a disruption affecting all Citrix services, but a security problem in customer-managed NetScaler installations that requires swift action.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical severity, the product versions involved and the active exploitation have been confirmed by Citrix and the NCSC. The article clearly distinguishes between a potential consequence and disruptions actually reported in the Netherlands.
- confirmed Citrix published a bulletin on eight vulnerabilities in NetScaler ADC and Gateway. — This is stated in Citrix's security bulletin. source
- confirmed CVE-2026-88771 and CVE-2026-88772 are being actively exploited. — Citrix and the NCSC report observed exploitation. source
- confirmed Both vulnerabilities have a CVSS score of 9.5. — The NCSC advisory refers to the scores for both CVEs. source
- confirmed Z-CERT warned healthcare organisations and advised, among other measures, temporarily disabling systems or monitoring them more closely. — This is mentioned in Z-CERT's warning. source
- confirmed The NCSC advises taking possible earlier compromise into account. — This is stated explicitly in the NCSC's recommendations. source
- confirmed There is no complete public overview of disruptions in the Netherlands. — The public advisories consulted report warnings and measures, but no nationwide inventory of disruptions. source
Editor's note
Active exploitation and the need for patches have been confirmed by Citrix and the NCSC. Public sources do not confirm which Dutch organisations actually shut down patient portals or home-working services.Sources
- Security Advisory NCSC-2026-0394 — Nationaal Cyber Security Centrum
- Citrix NetScaler ADC and Gateway Security Bulletin — Citrix
- Z-CERT waarschuwt zorgsector voor kritieke Citrix-kwetsbaarheden — Z-CERT
More on this in Dutch media
- de Volkskrant — „citrix netscaler”
- NOS — „citrix netscaler”
- Het Parool — „citrix netscaler”