Cyberattacks Force Dutch Hospitals and Government Offices to Shut Down Remote Systems
The Hague, Monday, 28 September 2026.
Critical security flaws in Citrix NetScaler have forced Dutch hospitals and government agencies to disable remote access systems immediately to prevent active cyberattacks.
Emergency Shutdowns Disrupt Dutch Healthcare and Government
Over the weekend of September 26–27, 2026, critical infrastructure across the Netherlands faced severe operational disruptions as organizations scrambled to disconnect their Citrix NetScaler environments [5]. Among those heavily impacted were several prominent Dutch medical institutions, including the Amphia Hospital in Breda, Elisabeth-TweeSteden Hospital in Tilburg and Waalwijk, and Frisius MC in Leeuwarden [5]. By shutting down these digital gateways, the hospitals effectively blocked remote access for both patients and healthcare employees to prevent potential network compromises [5]. While on-premises office desktop access remained largely functional, remote login capabilities and Citrix-hosted applications were completely severed [5].
The Warning Chain and Pre-Notification Protocol
The rapid shutdown of these systems was triggered by early warnings from national cybersecurity authorities. The Dutch National Cyber Security Centre (NCSC-NL) received critical intelligence regarding the vulnerabilities from a European partner Computer Emergency Response Team (CERT) [3]. Recognizing the immediate danger, NCSC-NL issued a private, restricted TLP:AMBER pre-notification to designated Dutch organizations [3][7]. This early warning allowed IT suppliers and Managed Detection and Response (MDR) providers to advise administrators to pull the plug and take NetScaler systems offline immediately, even before official software patches were publicly released by the vendor [3][7].
Understanding Citrix NetScaler’s Role and Innovation
Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway represent key innovations in enterprise networking, designed to optimize, secure, and control how applications and cloud services are delivered to end-users [GPT]. Operating as a secure entry point, the technology load-balances network traffic and provides virtual private network (VPN) access, making it essential for telecommuting and remote operations in modern enterprise and public sector environments [GPT]. The technology is developed by Citrix, which is owned by Cloud Software Group [8]. However, the provided source materials do not specify the physical headquarters or exact location of Citrix or Cloud Software Group [alert! ‘The exact physical location or headquarters of Citrix and Cloud Software Group is not provided in the source materials’].
The Technical Mechanics of the Exploits
Despite its security benefits, the system’s core architecture became the target of highly sophisticated attacks. Security investigations revealed that the zero-day exploits target the proprietary native C/C++ packet processing engine, known as ‘nsppe’, running on the FreeBSD-based kernel of the NetScaler appliance [8]. By exploiting these vulnerabilities, external threat actors can bypass standard authentication mechanisms entirely, allowing them to execute arbitrary commands and inject malicious shellcode directly into memory [1][8]. This execution occurs under root or ‘nobody’ service contexts, granting attackers deep administrative control over the compromised network gateway [8].
The Anatomy of the Critical Zero-Days
The emergency response centered on two highly critical security flaws, both carrying a maximum severity Common Vulnerability Scoring System (CVSS) score of 9.5 [1][6]. The first, tracked as CVE-2026-88771, is an improper input validation vulnerability that affects all default NetScaler ADC and Gateway configurations, enabling unauthenticated remote code execution (RCE) without requiring any special user accounts [1][6]. The second, CVE-2026-88772, is a memory buffer overflow vulnerability that triggers remote code execution or a denial-of-service (DoS) state when Datagram Transport Layer Security (DTLS) is enabled—which is the default configuration for most VPN virtual servers [1][6].
CISA Steps In as Global Attacks Escalate
As the scale of the threat became clear, the United States Cybersecurity and Infrastructure Security Agency (CISA) intervened. On September 27, 2026, CISA officially added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog [1][6][7]. The agency confirmed that threat actors are actively exploiting these vulnerabilities on a global scale [7][8]. CISA strongly urged public and private sector administrators to review Citrix’s advisories immediately, recommending that organizations perform forensic checks for indicators of compromise prior to patching, as applying updates can overwrite crucial forensic data [7][8].
Urgent Remediation and System Rebuilds Required
To mitigate the threat, Cloud Software Group released security bulletin CTX697096 on September 27, 2026, addressing a total of eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778) [6][8]. While Cloud Software Group updated its managed cloud services automatically, administrators of customer-managed deployments must manually apply the patches [3]. Fixed builds include NetScaler ADC and Gateway versions 14.1-73.37 and 13.1-64.23 [3][8]. Additionally, mitigating CVE-2026-88778 requires administrators to explicitly enable ‘Enhanced ISN Generation’ in their configurations [6].
Drastic Recovery Steps for Compromised Networks
For organizations that suspect their NetScaler systems were compromised prior to patching, the recovery process is demanding. Cybersecurity experts warn that simply applying the software update is insufficient to evict an active threat actor [8]. Affected organizations are advised to take drastic remediation steps, which include revoking all active certificates and associated private keys, resetting passwords for all connected service accounts—such as LDAP, RADIUS, OAuth, API, and SNMP—rotating all user credentials, and potentially rebuilding physical MPX hardware appliances from scratch to ensure no persistent backdoors remain [8].
Bronnen
- securityaffairs.com
- www.reddit.com
- www.bleepingcomputer.com
- www.facebook.com
- www.techzine.eu
- watchtowr.com
- www.securityweek.com
- www.thestack.technology