VMTech
Discuss a project

Researchers find extensive security flaws across Polish public websites

Researchers find extensive security flaws across Polish public websites

Security researchers Robert Kruczek and Kamil Szczurowski told the Def Con conference in Las Vegas that their scan of Poland’s public web identified more than 10,000 affected public entities and 250,000 websites with security flaws. The findings included systems used by airports, hospitals, government offices and courts.

The pair said they began the research to understand the condition of Poland’s public-facing internet and help make it safer. Their work highlighted how vulnerable software, unsupported products and difficult disclosure processes can leave public services exposed to hijacking and other attacks.

Pad CMS weaknesses reached public services

Kruczek and Szczurowski examined Pad CMS, a widely used content management system for organising and displaying website content. They identified critical vulnerabilities in the product that could be exploited with little effort.

One Pad CMS flaw allowed access to more than 300 public websites without a password. The developer did not issue a patch because the software had reached end of life and was no longer supported.

A separate vulnerability gave the researchers access to websites belonging to about 245 courts, which they described as roughly two-thirds of Poland’s judiciary. The scale of the affected court systems illustrates the concentration risk created when many public institutions depend on the same web platform.

Disclosure remains part of the security problem

The researchers reported their findings to the Polish government through official channels. They said the process was ultimately worthwhile and that the disclosures had made the environment “a little bit more safe.”

However, they also pointed to a lack of bug-bounty programmes and clear avenues for reporting flaws. Some vulnerabilities were easy to exploit, they said, but vendor responses did not always treat reports with sufficient urgency and sometimes characterised them as inconveniences.

Why public-facing assets need closer control

The research arrives while Poland is strengthening cyber defences after suspected Russian attacks on energy and water providers. The reported incidents have included attacks that exploited weak cybersecurity, making the exposure of public web systems a wider resilience concern.

For organisations operating public services, the practical implication is to maintain an accurate inventory of internet-facing sites, identify end-of-life software, define ownership for remediation and provide a clear channel for responsible vulnerability reports before routine weaknesses become an operational security issue.

#cybersecurity#poland#vulnerabilitymanagement#websecurity
Open analytics
On the site 0 views
min read 3 07.08.2026
Instagram

Researchers find extensive security flaws across Polish public websites

Open the post on Instagram ↗