October 1, 2026 Full Control of the Gateway, No Password Needed: The Citrix NetScaler Zero-Days (CVE-2026-88771/88772) and What They Mean for Your Practice
Late in September, security agencies across Europe and North America sounded an unusually loud alarm. Two previously unknown flaws in Citrix NetScaler — a widely deployed remote-access and traffic-management appliance — were being actively exploited to seize complete control of the devices. The response was telling: Dutch hospitals and government bodies did not wait for a fix to be scheduled. They pulled their remote access offline entirely. When hospitals disconnect rather than risk staying online, it is worth understanding what happened and why it reaches well beyond the organizations that run NetScaler themselves.
The two flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on September 27, with federal civilian agencies ordered to remediate them — and perform forensic triage for signs of compromise — by September 30. That is about as urgent as government cybersecurity directives get.

What NetScaler is, and why a gateway flaw is so dangerous
NetScaler ADC is an application-delivery and security platform that manages network traffic and acts as a firewall for applications. NetScaler Gateway is the companion remote-access and VPN product that lets staff outside the building connect securely to internal systems. In other words, these appliances sit at the very edge of a network, facing the public internet, and their whole job is to be the trusted doorway into everything private behind them.
That placement is exactly what makes a flaw in them so severe. A vulnerability in an ordinary workstation compromises one computer. A vulnerability in the gateway compromises the door to the entire internal network. As the Dutch national cyber center put it bluntly, one of these flaws “gives attackers full control of the gateway, providing direct access to the internal corporate network behind it.”
No login required
The most alarming detail is how little the attacker needs. CVE-2026-88771 stems from improper input validation and lets a remote, unauthenticated attacker run arbitrary commands on a device in its default configuration — no password, no stolen credential, and no user interaction of any kind. CVE-2026-88772 is a memory-overflow flaw that can lead to remote code execution or a denial-of-service crash; it too needs no login, and it affects appliances with the DTLS protocol enabled, which is the default for virtual VPN servers. The two can be exploited independently of each other.

Attackers used the flaws as zero-days — meaning they were in active use before any patch existed — to plant webshells, small hidden programs that give persistent remote control of the compromised appliance. Security researchers reported the attacks had been unfolding quietly for weeks, and assessed that the sophistication pointed more toward well-resourced, nation-state-aligned espionage than opportunistic criminals, though ransomware groups have a long history of targeting these same appliances. Citrix has since released patches covering the exploited flaws and six related ones.
“But we don’t run Citrix” — why this still matters to a dental practice
Most dental offices do not operate a NetScaler appliance; it is enterprise-grade equipment found in hospitals, large clinics, insurers, and the managed-service providers that support them. So why should a practice care? Two reasons.
First, your data lives in more places than your office. The hospitals, dental service organizations, insurers, billing clearinghouses, and imaging-sharing networks your practice exchanges information with are exactly the kind of organizations that run gateways like this. A breach of one of their edge devices can expose the patient data you sent them, entirely outside your walls. This is the same third-party exposure that turned a vendor compromise into a patient-notification problem for thousands of practices — the lesson that your security perimeter now includes everyone you share records with.
Second, and more directly, your practice almost certainly has edge devices of its own. A firewall, a VPN appliance, a remote-desktop gateway, or a router with a management page reachable from the internet is the same category of target — a public-facing box whose compromise opens the internal network. When routine Windows updates disrupted Always On VPN for practices with remote workers, it was a reminder of how much quiet dependence a modern office has on remote-access plumbing. The Citrix story is the same plumbing, failing in a far more dangerous way.
The pattern you should recognize by now
If this feels familiar, it should. A critical, pre-authentication flaw in the infrastructure that manages or protects a network — rather than in an everyday app — has become one of the dominant attack patterns of the year. We saw it when a perfect-10 zero-day in the N-central platform that IT providers use to manage client networks demanded an emergency patch, and again in the way attackers increasingly abuse legitimate remote-access tools to move through a practice unnoticed. The common thread is that the tools built to give trusted remote control are precisely the ones attackers most want to own.
What to actually do
You do not need to be a Citrix administrator to take sensible action this week.

- Inventory your internet-facing devices. Ask your IT provider for a plain list of everything in your practice reachable from the internet — firewall, VPN, remote-desktop gateway, router management, cameras. You cannot protect what you do not know is exposed.
- Ask your IT provider the direct question. “Do we, or any system you manage for us, run Citrix NetScaler ADC or Gateway? If so, is it patched to the fixed version, and has it been checked for signs of prior compromise?” A patch alone is not enough here — because exploitation predates the fix, authorities required forensic triage to confirm no webshell was already planted.
- Put edge devices on a patch SLA. Public-facing appliances should be patched on a defined, fast timeline, not whenever someone gets to it. The window between disclosure and exploitation is now measured in days, sometimes hours.
- Query your vendors and partners. For the organizations that hold your patient data — billing services, DSOs, insurers, imaging networks — it is reasonable to ask whether they were affected and what they did about it. Their breach is your breach notification.
- Segment and monitor. Ensure a compromised edge device cannot reach your imaging server, practice-management database, and backups without controls in the way, and that unusual activity on those systems raises an alert.

The takeaway
The Citrix NetScaler zero-days are a sharp reminder that the most valuable target on a network is often not a computer at all, but the device standing guard at its edge. When that device can be taken over with no password and no warning, the only defenses are speed and visibility: knowing exactly what you expose to the internet, patching it fast, and verifying — not assuming — that the partners holding your patient data have done the same.

How Compudent Systems can help
At Compudent Systems, we help dental practices across the GTA and Ontario get their arms around exactly this kind of risk — building a clear inventory of every internet-facing device, keeping firewalls and remote-access appliances patched on a tight timeline, segmenting the network so a single compromised device cannot reach your patient records and backups, and helping you ask the right questions of the vendors who hold your data. If you are not certain what your practice exposes to the internet right now, that uncertainty is the risk. Contact Compudent Systems for a remote-access and perimeter security assessment, and let us confirm your doorways answer only to you.
Sources & further reading:
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway – CISA
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation – The Hacker News
Related Reading
- Critical CVE-2026-3055 Citrix NetScaler Vulnerability Under Active Reconnaissance: Dental Practices Must Act Immediately
- A Single Packet, No Password Required: The Actively Exploited Windows IKE Flaw (CVE-2026-33824) and Your Practice
- The Gateway That Lets Your Team In Can Let Attackers In Too: Critical Check Point VPN Flaws (CVE-2026-85102 / 85103) and Your Practice