Skip to main content
Previous articles

Operations

Preparing Inspection Protocols for Gateway Vulnerabilities

Federal alerts targeting remote access and network tools require practices to establish forensic check protocols before updating software.

September 28, 2026 · 2 min read

In brief

  • CISA has added critical vulnerabilities in Citrix NetScaler, Mikrotik RouterOS, Microsoft SharePoint, and WordPress Core to its Known Exploited Vulnerabilities Catalog.
  • Active zero-day exploits in Citrix gateways permit remote code execution, threatening remote EHR connections and telework access with total post-exploitation control.
  • Practices should prepare IT protocols to inspect appliances and preserve forensic evidence before applying vendor patches, which can erase breach records.

Why it matters

CISA warnings highlight that attackers are actively exploiting flaws in everyday practice tools, including remote EHR gateways, internal document management, and public websites. When a remote access gateway or network router is compromised, attackers can gain total control of the environment. Practices must understand their exposure across these systems and ensure IT teams do not prematurely patch over active intrusions.

The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities Catalog to include actively targeted flaws in Citrix NetScaler ADC and Gateway, Microsoft SharePoint, Mikrotik RouterOS, and WordPress Core. Malicious cyber actors are using these vulnerabilities to target publicly exposed assets.

For practices relying on Citrix NetScaler appliances for remote EHR access and staff telework, CISA warned of critical zero-day vulnerabilities, including CVE-2026-88771 and CVE-2026-88772. Threat actors actively exploit these remote code execution flaws to achieve total control after compromise.

The alert introduces an important operational hurdle for medical groups. While vendor remediation is necessary, updating systems can erase evidence of an existing compromise. If a breach is suspected, technical teams must inspect appliances for indicators of compromise and preserve forensic evidence before vendor patches are deployed.

Similar exposure risks are surfacing across core clinical and administrative tools. CISA also added an actively exploited WordPress Core remote file inclusion flaw, CVE-2026-87902, threatening public practice websites, alongside flaws in Microsoft SharePoint document management and Mikrotik practice networking hardware.

Rather than treating each security bulletin as an isolated maintenance task, practice leadership should prepare their IT support and managed service providers to verify whether systems were breached prior to applying fixes.

CareScope take

Do not let your IT vendor blindly install updates across exposed infrastructure without first verifying appliance integrity. The critical lesson from CISA alerts is that premature patching can destroy evidence of an active intrusion. Prepare your administrative team now to require documented inspection of Citrix gateways and network hardware before software updates are finalized.

Sources

A quick note from Owen

CareScope works best with your phone upright. Turn it the other way to continue.