Once again, a vulnerability in the Citrix NetScaler system has disrupted Dutch organizations. As a result, hospitals and the national government shut down their systems last weekend. Patients can’t access their medical records, and government employees working from home cannot log in. The NCSC reports that the vulnerabilities have since been resolved.
Large organizations, hospitals, and banks widely use NetScaler as a load balancer. It distributes incoming traffic across multiple servers. However, the system has proven to be vulnerable on multiple occasions. For example, a vulnerability disrupted the Dutch judicial system in mid-2025, when the systems were taken offline.
Now, another vulnerability has been discovered. In a security bulletin, Citrix confirms multiple vulnerabilities in NetScaler ADC and NetScaler Gateway. Affected versions include 14.1 prior to 14.1-73.37 and 13.1 prior to 13.1-64.23, as well as the FIPS and NDcPP variants. Secure Private Access Hybrid environments running on NetScaler instances are also vulnerable.
The bulletin applies only to customers who self-manage their NetScaler. Cloud Software Group, Citrix’s owner, has updated Citrix-managed cloud services and Adaptive Authentication.
Hospitals are shutting things down
Z-CERT, the center of expertise for cybersecurity in healthcare, issued a precautionary warning to healthcare institutions. It referred to “critical vulnerabilities” and recommended measures, including shutting down systems. Healthcare institutions use NetScaler to provide patients with remote access to their online medical records.
The Amphia Hospital in Breda and the Elisabeth-TweeSteden Hospital in Tilburg and Waalwijk were affected, according to the NOS. Doctors at the hospital can still view patient records, but patients themselves cannot. Healthcare services at Amphia are continuing as usual. At Frisius MC in Leeuwarden, the issues have since been resolved; that hospital had “shut down a few digital systems” without affecting patient care.
Central government disconnects Citrix from the internet
The national government also took action. The Ministry of the Interior announced that Citrix had reported serious security risks in some of its products. As a precaution, the national government subsequently disconnected all Citrix environments from the internet. As a result, government employees working from home cannot log in, and some applications running on Citrix are not functioning. Those working at the office on a desktop computer can almost always access their work environment.
The NCSC warns that the two zero-days, CVE-2026-88771 and CVE-2026-88772, are being actively exploited. The first allows an attacker to strike remotely without logging in. The second is a memory overflow that can lead to remote code execution or a denial of service, especially when DTLS is enabled.
Citrix recommends that administrators update to the appropriate builds immediately. There are no other mitigations available.
Tip: Citrix vulnerability affects several critical Dutch organizations