Citrix cybersecurity
– urzine/Getty Images

Citrix patched vulnerabilities affecting its NetScaler application delivery controller and gateway lines, with critical Dutch organizations shutting down their systems in response.

Techzine reports The Netherlands' Ministry of the Interior took all Citrix environments offline over the weekend, while patients of two major hospitals in that country were unable to view their records. A third hospital, Frisius MC in Leeuwarden, shut down some of its digital systems as a precaution.

The issues stem from the in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772. The former vulnerability runs the risk of remote code execution due to improper input validation on all NetScaler ADC and NetScaler Gateway devices, while the latter runs the same risk via a memory overflow vulnerability. Both were rated CVSS 9.5.

Citrix released patches for both lines to cover CVE-2026-88771 through CVE-2026-88778. Customers were advised to install NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases; ADC and Gateway 13.1-64.23 and later releases of 13.1; NetScaler AD 14.1-73.37 FIPS and later releases of 14.1-FIPS; and ADC 13.1-FIPS, 13.1-NDcPP 13.1.37.279, plus later releases of 13.1-FIPS and 13.1-NDcPP.

Due to the severity of the situation, Citrix made generic indicators of compromise (IoCs) available through NetScaler Console to help users quickly perform an initial assessment of whether NetScaler deployments may have been affected.

The feature is available in the NetScaler Console service and NetScaler Console on-premises with Cloud Connect, starting with version 14.1-73.36. It will appear only after Citrix releases the IoC functionality and requires the telemetry channel to be enabled.

While this is a global issue for Citrix customers, only Dutch organizations thus far have publicly reported issues caused by the flaws.