Skip to content
Gradient Background
Bruce Cullen10/06/20263 min read

The Patch Was Ready. The Hospital Still Went Dark.

NetScaler CVE-2026-88771: Why a Patch Wasn't Enough.
3:23

NetScaler CVE-2026-88771: Why a Patch Wasn't Enough.

A patch existed. And a government ministry still took every Citrix environment it had offline for a weekend.

That's the part of last week's NetScaler story I can't stop thinking about.

What happened

In late September, Citrix patched two critical NetScaler ADC and Gateway bugs, CVE-2026-88771 and CVE-2026-88772. Both are remote code execution. Both scored CVSS 9.5. Both were already being exploited in the wild, per SDxCentral.

The fallout landed hardest in the Netherlands. The Ministry of the Interior took all of its Citrix environments offline over the weekend. Patients at two major hospitals couldn't see their own records. Frisius MC in Leeuwarden switched off some digital systems as a precaution.

Those are just the ones who said so out loud. This was a global bug.

What it means for you

If you run anything that sits between your people and their apps, this was your weekend too. Maybe not the gateway. But the next patch, the next zero-day, the next "upgrade by Monday or else."

The patch is ready. Are your workflows? Connect, open the app, complete the work: validate the workflows your people depend on.

And here's the uncomfortable thing. When the fix is sitting right there and you still choose to pull the plug, the problem isn't the patch. It's that you can't prove what the patch will do to everything downstream before you ship it.

So you pick between two bad options:

  • Ship it blind and hope the clinical app, the VPN client and the fifteen line-of-business tools behind it still work Monday.
  • Go dark and take the outage on purpose, because a known outage beats an unknown one.

The Dutch ministry picked option two. Honestly, I'd probably have done the same. That's the problem.

The gap nobody's saying out loud

We've spent a decade getting faster at finding holes and faster at shipping fixes. Detection is fast. Patching is fast.

The middle isn't. The bit where someone confirms that the fix doesn't break the workflow a nurse needs at 7 a.m. still takes days or weeks of people clicking through apps by hand. When attackers are already inside, you don't have weeks. So the middle gets skipped, or the whole service gets switched off.

The hole isn't the risk anymore. The fix is.

Where we come in

ATP360 won't patch your gateway. It's built for the middle. The endpoints and apps on the other side of it.

When a change lands — a Windows update, a new Citrix Workspace app build, an app update your vendor pushed overnight — ATP360 runs your real workflows against it, in your tenant, on real endpoints. Production is never touched. You get evidence: screenshots, logs, pass/fail by step. Then a human makes the call.

What that looked like in a recent run: a 13-stage build validated in 23 minutes. Work that used to take three weeks.

Proof before production: a 13-stage build validation went from 3 weeks to 23 minutes, with screenshots, step results and logs. AI runs the validation. Your team makes the call.

3 weeks → 23 minutes. Same build. Measured, not modeled.

That's the difference between "we turned it all off to be safe" and "we patched Saturday morning and we have the receipts."

One ask

Send us your scariest app. The one you'd least want to break on a weekend like that. We'll validate a real change against it, live, and you can watch.

Talk to us

P.S. ATP360 runs when you trigger it, per change. It isn't magic and it doesn't replace your patching tool or your detection. It sits between them so the person signing off has evidence instead of a gut feeling.

RELATED ARTICLES