Key takeaways
- Researchers discovered 10,000 Polish public entities with 250,000 vulnerable websites, including critical infrastructure like courts, airports, and hospitals.
- A vulnerability in Pad CMS enabled password-free access to 300+ websites and affected two-thirds of Poland's judiciary.
- Systemic problems—unsupported software, missing patches, and absent bug bounties—left Polish public infrastructure exposed to cyberattacks.
At DefCon 2026 in Las Vegas, Polish security researchers Robert Kruczek and Kamil Szczurowski shared the results of an ambitious project: mapping the security posture of their country’s public web infrastructure. What began as an effort rooted in patriotism—a desire to understand and improve the safety of Poland’s digital ecosystem—evolved into a sobering catalog of systemic vulnerabilities affecting thousands of government agencies.
The Scale of Vulnerability
The numbers told a troubling story. The researchers identified more than 10,000 affected public entities operating approximately 250,000 websites containing exploitable security flaws. The affected organizations spanned critical infrastructure: airports, hospitals, local government offices, and national agencies all exposed to potential compromise. The breadth of the problem suggested that vulnerability was not concentrated in a few negligent institutions but rather reflected deeper patterns of neglect across Poland’s public sector.
Why Vulnerabilities Persisted
Kruczek and Szczurowski identified several systemic factors enabling the vulnerabilities to flourish. Many of Poland’s public websites relied on outdated software that no longer received security patches. Software vendors had either abandoned support for these products or charged fees that public agencies could not or would not pay. Equally troubling was the absence of formal bug bounty programs or established channels for reporting vulnerabilities responsibly. When researchers did attempt to disclose flaws, some vendors dismissed the reports or treated them as minor inconveniences rather than urgent security matters requiring immediate remediation.
Patch Fatigue and Negligence
The researchers discovered that even when patches existed, many organizations failed to apply them. Legacy systems, fear of disrupting operations, and limited IT resources meant that updates accumulated in backlogs or were ignored entirely. This pattern repeated across dozens of organizations, creating overlapping windows of vulnerability.
Pad CMS: A Widespread Risk
The research highlighted a specific and dramatic vulnerability in Pad CMS, a content management system widely deployed across Poland’s public agencies. The researchers uncovered critical flaws that allowed them to gain unauthorized access to websites without any authentication mechanism—effectively, password-free entry. More than 300 public websites using Pad CMS were vulnerable to this attack.
The vendor’s response exemplified the core problem: the company had moved Pad CMS to “end of life” status, meaning it no longer received technical support or security patches. Despite the known vulnerability affecting hundreds of active public websites, the vendor declined to issue a fix. Organizations using Pad CMS faced a choice between accepting the risk or bearing the cost and operational burden of migrating to alternative platforms.
The Judiciary Under Threat
Among the most alarming findings was the vulnerability of Poland’s court system. The researchers identified exploitable flaws affecting the websites of approximately 245 courts—representing roughly two-thirds of Poland’s entire judiciary. The same vulnerability patterns discovered elsewhere, particularly those involving Pad CMS and other unsupported software, created unauthorized access points into the digital infrastructure supporting the country’s legal system.
A court website compromise could expose case information, judicial records, or attorney communications. The implications extended beyond data theft; attackers could potentially manipulate case records, alter documents, or disrupt court operations. The researchers emphasized that despite the criticality of judicial infrastructure, the same systemic weaknesses plaguing other public agencies remained unaddressed in courts as well.
Systemic Weaknesses
The Absence of Accountability
Poland’s public sector lacked mechanisms for identifying and addressing security vulnerabilities at scale. No unified cybersecurity standards applied across government agencies. No mandatory reporting requirements forced vendors to disclose when software reached end-of-life status or would no longer receive security patches. Government procurement policies did not consistently prioritize security or require vendors to maintain software for a minimum period.
The Cost Factor
Many public agencies operated under tight budgets. Transitioning from one content management system to another required spending that competing priorities made difficult to justify. IT staff in smaller agencies lacked the expertise to evaluate security risks or understand the implications of running unsupported software. The researchers found that some organizations acknowledged the vulnerabilities but deemed remediation financially infeasible.
The Russian Context
The research arrived at a moment of heightened concern about Poland’s cybersecurity. The country had recently experienced a wave of suspected Russian cyberattacks targeting critical infrastructure, particularly energy and water utilities. Security officials attributed some of those incidents to attackers exploiting weak security practices and outdated systems—exactly the vulnerabilities Kruczek and Szczurowski had documented across the public web.
The timing suggested that foreign adversaries might be motivated to exploit the same vulnerabilities the researchers had discovered. Airports, hospitals, and government offices represented high-value targets for espionage or disruption. The unpatched systems and missing security controls the researchers found could provide straightforward entry points.
The Path Forward
Rather than publicly releasing their findings immediately, Kruczek and Szczurowski followed responsible vulnerability disclosure practices. They reported their discoveries through official government channels, giving Polish authorities the opportunity to address the most critical vulnerabilities before public awareness could draw unwanted attention from malicious actors.
The researchers acknowledged the effort required for this process. Coordinating with multiple agencies, explaining technical vulnerabilities to non-technical officials, and waiting for remediation could be frustrating work. Yet they emphasized that the hassle was worthwhile: as a result of their disclosure, Poland was “a little bit more safe.”
The research exposed a challenge facing many countries’ public sectors: the gap between security requirements and the resources, expertise, and processes available to meet them. Poland’s situation was likely not unique. Many democracies operated critical public websites on outdated, unsupported software. Many lacked bug bounty programs or clear vulnerability reporting mechanisms. The researchers’ work served as a reminder that cyber resilience required not just technical fixes but organizational and procurement changes.
Frequently Asked Questions
What scale of vulnerabilities did the Polish researchers document?
The researchers identified more than 10,000 affected public entities operating approximately 250,000 websites with exploitable security flaws, including airports, hospitals, courts, and government offices.
How did the Pad CMS vulnerability impact Polish courts?
Critical vulnerabilities in Pad CMS allowed password-free access to over 300 public websites and affected approximately 245 courts, representing roughly two-thirds of Poland's entire judiciary.
Why did the researchers' findings matter at that particular time?
Poland had recently experienced suspected Russian cyberattacks on energy and water infrastructure, making the researchers' discoveries about widespread vulnerabilities in public systems especially urgent.