Poland Cybersecurity Scan Exposes 250,000 Vulnerable Public Websites
Polish researchers found flaws across 250,000 public websites, exposing 10,000 entities, 245 courts, hospitals and airports to potential cyberattacks.
Summary
TechCrunch reported on August 7, 2026, that Polish security researchers Robert Kruczek and Kamil Szczurowski told Def Con in Las Vegas they had found flaws across 250,000 websites belonging to more than 10,000 public entities, including government offices, airports and hospitals. Motivated by patriotism and public safety, they found buggy vendor software, missing bug bounty programs and inadequate reporting routes left services exposed to hijacking and other attacks, while some vendors dismissed easily exploited flaws as inconveniences.
Critical vulnerabilities in the widely deployed Pad CMS let the researchers access more than 300 public websites without passwords, but its developer declined to patch the unsupported, end of life software. Another flaw opened websites serving about two thirds of Poland’s judiciary, roughly 245 courts. The findings come amid suspected Russian attacks on Polish energy and water providers that have exploited weak security. Kruczek and Szczurowski reported the vulnerabilities through several official government channels and said the difficult process ultimately made Poland somewhat safer.
Positives
- The scan identified security flaws across 250,000 public websites before attackers could potentially exploit them.
- Kruczek and Szczurowski reported their findings through several official Polish government channels.
- More than 300 passwordless Pad CMS exposures and roughly 245 vulnerable court websites were specifically documented.
- The researchers said the difficult disclosure effort ultimately made Poland somewhat safer.
Risks & concerns
- More than 10,000 Polish public entities, including airports, hospitals and government offices, had websites with security flaws.
- Pad CMS vulnerabilities allowed access to more than 300 public websites without a password.
- About 245 courts, representing roughly two thirds of Poland’s judiciary, were accessible through another vulnerability.
- The Pad CMS developer declined to patch its unsupported, end of life software.
- Missing bug bounties, poor reporting routes and vendors dismissing flaws as inconveniences obstructed remediation.
- Suspected Russian attacks have already targeted Polish energy and water providers by exploiting weak cybersecurity.