Polish Researchers Find Thousands of Public Websites Vulnerable to Cyberattacks

Polish security researchers found vulnerabilities affecting more than 10,000 public entities and 250,000 websites, including courts, hospitals and airports.

Aug 9, 2026 - 10:47
 0
Polish Researchers Find Thousands of Public Websites Vulnerable to Cyberattacks
Image Credit: Chatgpt

Two Polish security researchers have uncovered widespread vulnerabilities across the country’s public internet, finding that more than 10,000 public entities and roughly 250,000 websites had security flaws that could expose them to cyberattacks.

Robert Kruczek and Kamil Szczurowski presented their findings at the Def Con cybersecurity conference in Las Vegas on Friday. The researchers said they began the project out of a desire to understand Poland’s cybersecurity posture and help make its public services safer.

Their research uncovered weaknesses affecting a wide range of public institutions, including hospitals, airports, government offices and courts. They said outdated vendor software, limited bug-reporting channels and the lack of bug bounty programs made it difficult for researchers to report vulnerabilities and get them addressed.

Some of the flaws were particularly easy to exploit, the researchers said, but were not always treated as serious security problems by vendors.

Hundreds of public websites exposed

Among the most serious findings were vulnerabilities in Pad CMS, a widely used content management system. Kruczek and Szczurowski said they were able to gain access to more than 300 public websites without needing a password.

The software’s developer had stopped supporting the CMS after it reached end-of-life status, leaving affected websites exposed to known vulnerabilities.

The researchers also identified another flaw that allowed them to access websites belonging to roughly two-thirds of Poland’s judiciary, or about 245 courts.

The findings come as Poland is working to strengthen its cyber defences following a series of suspected Russian attacks targeting critical infrastructure, including energy and water providers. Some of those attacks have exploited weak cybersecurity protections.

Findings reported to Polish authorities

Kruczek and Szczurowski said they reported the vulnerabilities to the Polish government through official channels. Their research highlights the risks created when public institutions rely on outdated software without effective systems for reporting and fixing security flaws.

Despite the difficulties involved in reporting the vulnerabilities, the researchers said their work ultimately made Poland’s public web infrastructure “a little bit safer”

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.