Two critical Citrix gateway bugs put hospital remote access at risk

A pair of NetScaler remote code execution flaws are already being exploited against the edge appliances hospitals use for clinician access.

MedRisk Staff
By
2 Min Read

The remote-access appliances that hospitals lean on for clinician VPNs took two critical hits this weekend. Citrix confirmed on September 27 that attackers had already exploited a pair of remote code execution flaws in NetScaler ADC and NetScaler Gateway, shipping fixes alongside repairs for six more bugs.

Both carry CVSS v4 scores of 9.5. CVE-2026-88771 is an input validation failure that lets an unauthenticated attacker run arbitrary commands, and it lands on every deployment running an affected build, default configuration included. CVE-2026-88772 is a memory overflow with the same outcome on appliances where DTLS is switched on, the default for VPN virtual servers.

Healthcare networks feel this class of flaw painfully. NetScaler gateways sit at the perimeter handling VPN, load balancing and authentication, so one unpatched box can hand an intruder a foothold deep inside clinical systems. That pattern is well worn: Clop’s crews spent 2023 and 2024 harvesting sessions from a NetScaler bug to reach healthcare and life sciences victims, and the same appliance class has stayed a favored entry point since.

WatchTowr flagged the unpatched flaws a day before Citrix’s bulletin, and some administrators pulled appliances offline while they waited. CISA added both issues to its Known Exploited Vulnerabilities catalog on September 27, setting a short federal remediation clock. Citrix published no workaround and no indicators of compromise, so patching is the only complete answer.

What hospital security teams should do now

Inventory every NetScaler ADC and Gateway instance, including units behind a load balancer or run by a hosting partner. Patch to the current fixed builds, then hunt for tampering – new local accounts, unexpected configuration exports, or sessions that outlive normal login windows. Where a fix cannot land immediately, cut the management interface off from the internet and rotate credentials on the device.

Share This Article