started · updated
Citrix vulnerabilities disrupt Dutch hospitals and government systems
Critical vulnerabilities in Citrix NetScaler software have caused widespread digital disruptions across the Netherlands, affecting both the healthcare sector and the national government.
Several hospitals, including Amphia in Breda, Elisabeth-TweeSteden Ziekenhuis (ETZ) in Tilburg, and Frisius MC in Friesland, took preventive measures by temporarily disabling patient portals or other digital services. This prevented patients from accessing medical records and appointment information online. While these outages impacted remote access, hospital staff maintained access to internal systems, and regular medical care continued without interruption.
The National Cyber Security Centre (NCSC) and Z-CERT confirmed that the vulnerabilities, specifically CVE-2026-88771 and CVE-2026-88772, were being exploited by attackers. In response, the Dutch national government disconnected Citrix environments from the internet to protect its networks, which limited remote work capabilities for civil servants. The Dutch police also implemented preventive measures that restricted teleworking. Citrix has since released security updates to address the flaws.
Entities
Amphia Hospital · Citrix · Elisabeth-TweeSteden Hospital · Elisabeth-TweeSteden Ziekenhuis · National Cyber Security Centre · Z-CERT
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Frisius MC in Friesland temporarily disabled digital services due to the vulnerabilities. www.security.nl · tpo.nl · nos.nl
- [● 3 SOURCES] The Dutch national government disconnected Citrix environments from the internet as a precaution. www.rd.nl · tpo.nl · nos.nl
- [● 5 SOURCES] Elisabeth-TweeSteden Ziekenhuis (ETZ) took preventive measures that temporarily blocked patient portal access. tilburgnieuwsjournaal.nl · www.security.nl · tpo.nl · nos.nl
- [● 4 SOURCES] Amphia Hospital in Breda disabled its patient portal as a preventive measure. tilburgnieuwsjournaal.nl · tpo.nl · nos.nl
- [● 2 SOURCES] Citrix confirmed that vulnerabilities CVE-2026-88771 and CVE-2026-88772 were being exploited by attackers. www.security.nl · tpo.nl
- [● 6 SOURCES] Z-CERT warned healthcare institutions about critical vulnerabilities in Citrix NetScaler. tilburgnieuwsjournaal.nl · www.security.nl · tpo.nl · nos.nl · www.omroepbrabant.nl
- [○ 1 SOURCE] The Dutch police implemented preventive measures that limited remote and home working. www.rd.nl
- [● 3 SOURCES] The NCSC reported that the Citrix vulnerabilities were being exploited. www.rd.nl · www.security.nl · nos.nl