Skip to main content
Previous articles

Operations

Urgent CISA Warnings on Remote Access and Practice Software

CISA has issued warnings regarding actively exploited vulnerabilities in Citrix gateways, Microsoft SharePoint, Mikrotik routers, and WordPress.

September 28, 2026 · 2 min read

In brief

  • Threat actors are actively exploiting critical zero-day flaws in Citrix NetScaler ADC and Gateway to execute remote code and gain total control.
  • Practices must inspect Citrix appliances for compromise and preserve forensic evidence before patching, as updates can erase breach evidence.
  • CISA has also added actively exploited vulnerabilities in Microsoft SharePoint, Mikrotik RouterOS, and WordPress Core to its catalog for urgent remediation.

Why it matters

Practices rely heavily on tools like Citrix for remote EHR access, SharePoint for internal document management, Mikrotik hardware for practice networking, and WordPress for public websites. Because cyber actors are actively targeting these specific systems to execute remote code and seize total control of publicly exposed assets, unpatched practice infrastructure faces immediate operational risk.

The Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances. These flaws, cataloged as CVE-2026-88771 and CVE-2026-88772, allow attackers to execute remote code and gain total control over publicly exposed assets.

Practices relying on Citrix gateways for telework or remote EHR access need to act immediately. CISA advises that IT support must inspect appliances for indicators of compromise prior to updating. If a breach is suspected, technical teams must preserve forensic evidence before applying vendor patches, because the patching process can erase evidence of compromise.

Citrix is not the only asset currently targeted in active attacks. CISA has also added known exploited vulnerabilities in Microsoft SharePoint and Mikrotik RouterOS to its catalog. Small and midsize practices frequently use SharePoint for clinic document management and Mikrotik hardware for clinic network routing.

Additionally, CISA cataloged an actively exploited remote file inclusion vulnerability in WordPress Core, designated CVE-2026-87902. Because many practices host their public-facing websites on WordPress, unpatched sites present another exposed vector for active compromise.

To mitigate risks to publicly exposed practice assets, practice administrators should immediately instruct their internal IT staff or managed service provider to confirm whether these systems are in use, inspect them for compromise, and carry out prioritized remediation.

CareScope take

Do not assume your managed service provider has automatically applied these updates. Ask your technical team today whether your practice uses Citrix NetScaler, SharePoint, Mikrotik routers, or WordPress, and instruct them explicitly to inspect Citrix gateways for active compromise and preserve forensic logs before deploying vendor patches.

Sources

A quick note from Owen

CareScope works best with your phone upright. Turn it the other way to continue.