Summary
- Dutch hospitals restricted patient access to online records following warnings over vulnerable NetScaler systems.
- Some government staff also temporarily lost remote access after Citrix applications were disconnected.
- The measures were precautionary; the public reports reviewed do not establish that the affected Dutch organisations were compromised.
Dutch hospitals and government organisations temporarily restricted Citrix-based remote services after national and international warnings over actively exploited NetScaler vulnerabilities, creating visible disruption even where compromise had not been established.
Several hospitals blocked patients from accessing online medical records over the weekend after the Netherlands’ National Cyber Security Centre warned about vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. Clinicians retained access to records at the affected institutions, but patients at some hospitals were temporarily unable to use online portals during consultations.
The impact extended beyond healthcare. The Dutch interior ministry said some civil servants were unable to work remotely after Citrix applications were switched off as a precaution. Services have since begun returning, but the interruptions provide an unusually clear example of the operational cost organisations sometimes accept when exposed infrastructure faces credible evidence of active exploitation.
Citrix disclosed eight vulnerabilities in the affected products. The most serious include CVE-2026-88771, an unauthenticated remote-code-execution vulnerability affecting NetScaler ADC and Gateway deployments including default configurations, and CVE-2026-88772, a memory-overflow flaw that can result in remote code execution or denial of service when DTLS is enabled.
The vendor says exploitation of both vulnerabilities has been observed against unmitigated deployments and has urged customers to install updated releases. The Dutch NCSC separately assigned a high priority to the advisory and identified affected versions of the customer-managed products.
The Dutch response illustrates the difficult decisions that accompany vulnerabilities in remote-access infrastructure. Gateways sit close to the boundary between internal systems and the public internet, and are routinely used to provide employees, contractors, and other users with access to applications that would otherwise remain inside organisational networks.
That makes the consequences of disconnecting them unusually visible. Taking a gateway offline can immediately remove a potential path into internal services, but it may also cut staff off from remote working systems or prevent patients and other users from reaching digital services. In hospitals, the distinction between clinical access and patient-facing access becomes particularly important: a defensive shutdown can be disruptive without necessarily compromising care delivery itself.
The disruption also separates two concepts that are often conflated during live cyber incidents. Evidence that a vulnerability is being exploited globally does not establish that every exposed organisation has been compromised. The public information reviewed for the Dutch institutions describes precautionary restrictions in response to the vulnerability warnings rather than confirmed intrusions at those hospitals or government departments.
The response adds an operational layer to Citrix’s disclosure of the exploited flaws: organisations still have to decide how much service interruption they are prepared to absorb while they update, investigate, and restore exposed infrastructure.
That trade-off is especially acute in healthcare and public administration, where remote access has become part of ordinary service delivery. The immediate incident may have been driven by a pair of NetScaler vulnerabilities, but the disruption demonstrates how infrastructure security decisions can propagate directly into public-facing availability even before an attacker is found inside the network.





