Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on September 27. Two of them, CVE-2026-88771 and CVE-2026-88772, carry a CVSS score of 9.5 each, and Citrix said it had already observed exploitation against unmitigated deployments before the advisory went out.

CVE-2026-88771 is an unauthenticated command injection reached through the /nf/auth/doAuthentication.do endpoint. It abuses ns_monuploadd_err.pl, a Perl script that processes crash logs, letting an attacker inject shell commands with no login required. CVE-2026-88772 is a memory overflow in the Packet Processing Engine's handling of DTLS handshakes, triggered by spoofing the fragment_length field small while the real payload runs larger. It needs DTLS enabled, the default on NetScaler Gateway VPN servers. Researcher Sina Kheirkhah of watchTowr published proof-of-concept research on both flaws in the days before Citrix's advisory.

CISA added both CVEs to its Known Exploited Vulnerabilities catalog the same day, setting a September 30 patch deadline for federal agencies. Fixed builds are NetScaler ADC and Gateway 14.1-73.37 and later, and 13.1-64.23 and later, with matching 14.1-FIPS and 13.1-FIPS or NDcPP builds. More than 50,000 internet-facing instances were still counted as exposed on the day the advisory shipped.

Three Dutch hospitals felt it within hours. Amphia in Breda and Elisabeth-TweeSteden in Tilburg and Waalwijk shut down systems as a precaution. Frisius MC in Leeuwarden disabled select systems, then restored them. Patients lost online access to their records while clinicians kept theirs, a split that only works when it has been planned for in advance. Z-CERT, the Dutch healthcare cyber center, recommended the shutdowns, and the national cyber authority confirmed the flaws were resolved once the appliances were patched.

The Netherlands has been here before. A NetScaler flaw disrupted part of the country's judiciary in mid-2025, and this is the second NetScaler zero day chain in three months to put device manufacturers on notice, after CVE-2026-8452 in August.

The appliance carries no patient data and touches no device firmware, and that is exactly why it gets treated as background infrastructure until it isn't. Manufacturers running NetScaler for remote service access or VPN termination into hospital networks inherit this same clock. Citrix's own guidance says a fix does not evict an attacker who arrived first, so confirm exposure closed after checking, not after patching.