Polish cybersecurity researchers Robert Kruczek and Kamil Szczurowski have uncovered a broad set of weaknesses across the country's public web infrastructure, identifying more than 10,000 affected entities and around 250,000 websites with security gaps.
Presenting their findings at the Def Con conference in Las Vegas, the duo said their goal was to better understand the resilience of Poland's public internet and help strengthen it. Their scan revealed exposure across airports, hospitals, courts, and government offices.
Key Findings
One of the most serious issues involved Pad CMS, a widely used content management system. The researchers said critical flaws in the platform made it possible to access more than 300 public websites without a password. Because the software had reached its end of support, no patch was issued.
They also reported a separate vulnerability that could open access to roughly two-thirds of Poland's judiciary, affecting about 245 courts. According to the researchers, the findings were shared with authorities through official reporting channels.
The study highlights how stronger reporting systems, coordinated vulnerability disclosure, and modernized software maintenance can help public institutions stay ahead of emerging cyber risks. In the years ahead, such efforts may shape a more resilient digital public sector.