September 28, 2026
Citrix Zero-Day: How Vulnerable Is the Netherlands’ Digital Infrastructure?
A critical vulnerability in Citrix NetScaler is putting Dutch hospitals and government organizations under pressure. Patients temporarily…

By Jordi Been
3 min read
A critical vulnerability in Citrix NetScaler is putting Dutch hospitals and government organizations under pressure. Patients temporarily lose access to their medical records, civil servants can no longer work remotely, and security teams are forced to make decisions under intense time pressure. These events highlight how dependent our digital infrastructure has become on systems we take for granted every day.
On September 26, 2026, reports emerged of two newly discovered, actively exploited vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway.
NetScaler serves as a gateway to internal systems for many organizations. It is used for VPN connections, remote access, and load balancing. An attacker who exploits a vulnerability in such a system may be able to gain access to systems that would normally be protected by multiple layers of security.
On September 27, Citrix confirmed that two vulnerabilities were being actively exploited and released security updates. The vulnerabilities were assigned the identifiers CVE-2026–88771 and CVE-2026–88772.
The potential impact is significant. This is not simply a matter of installing a security update. Organizations must also consider whether attackers may have already gained access to their systems.
The consequences became visible in the Dutch healthcare sector over the weekend.
Several hospitals temporarily restricted access to patient environments. Amphia, Elisabeth-TweeSteden Hospital, and Frisius MC were among the organizations mentioned in media reports.
Patients temporarily lost access to their medical records through online portals. According to reports, healthcare professionals retained access to patient records.
Z-CERT, the cybersecurity center for the Dutch healthcare sector, warned affiliated organizations about the vulnerabilities and their potential consequences.
The impact was also felt within the government. According to media reports, employees of the Dutch Ministry of the Interior and Kingdom Relations were temporarily unable to work remotely after Citrix applications were taken offline.
These measures demonstrate how heavily organizations depend on systems that enable remote access. When the security of such a gateway cannot be guaranteed, shutting it down may become necessary.
At the same time, doing so directly affects the availability of digital services.
Patching does not automatically mean you are secure
One of the most important lessons from this incident is that installing a security update does not automatically mean a system is secure again.
If attackers have already exploited a vulnerability, they may have gained access before a patch became available. Installing an update does not necessarily remove that existing access.
Organizations must therefore do more than simply verify that their NetScaler systems have been updated. They must also investigate whether there are signs of a previous compromise.
This requires more than a technical update. It involves examining log files, network traffic, access permissions, and the potential impact on connected systems.
For security teams, this means answering several questions under time pressure: Which systems are vulnerable? Which services depend on those systems? And what measures are necessary to prevent further damage?
The real question: How resilient are we?
The Citrix incident highlights how heavily organizations depend on centralized access systems. A single vulnerable component can affect access to medical records, government services, and internal business processes.
The challenge is not simply to apply patches as quickly as possible. It is also about whether organizations are prepared to temporarily shut down critical systems, whether alternative procedures are available, and whether security teams have sufficient information to make timely decisions.
For hospitals, temporarily disabling an access system may mean that patients can no longer use certain digital services. For government organizations, it may mean that employees are temporarily unable to work remotely.
This makes cybersecurity more than a technical issue. It also becomes a question of operational continuity and service availability.
What can we learn from this?
The events of September 2026 demonstrate that the resilience of digital infrastructure depends not only on technology itself but also on how well organizations prepare for incidents.
Organizations must know not only how to remediate a vulnerability but also how to maintain essential services when a critical system becomes temporarily unavailable.
This requires effective incident response, a clear understanding of system dependencies, and well-defined agreements between IT, security, and the business units responsible for service delivery.
The Citrix vulnerabilities serve as a concrete reminder of a fundamental challenge: How do we keep our digital infrastructure available and secure when a critical component comes under attack?
Because when a gateway proves vulnerable, the question is not just how quickly we can fix it. The question is also what happens when we have to shut it down.