
Table of Contents
Introduction
A major Polish web security investigation has uncovered serious vulnerabilities across the country’s public internet infrastructure, raising concerns about the safety of government services and critical public institutions.
Two Polish security researchers, Robert Kruczek and Kamil Szczurowski, examined the country’s public-facing websites to understand how exposed Polish institutions were to potential cyberattacks. Their research reportedly identified more than 10,000 public entities and around 250,000 websites with security flaws, including websites connected to courts, hospitals, airports and government offices.
The findings highlight how outdated software, weak security practices and limited vulnerability-reporting systems can create significant risks for public services.

Researchers Investigate Poland’s Cybersecurity Exposure
The researchers began their investigation out of concern for their country’s digital security.
Rather than focusing on one particular institution, they looked across Poland’s public web infrastructure to identify weaknesses that could potentially be exploited by attackers.
Their findings showed that Polish web security problems were not limited to a small number of isolated websites. Instead, vulnerabilities appeared across a broad range of public-sector services.
Some of the affected systems were reportedly associated with important institutions, including courts, healthcare organisations, airports and government offices.
The researchers presented their findings at the DEF CON cybersecurity conference in Las Vegas, where they explained how weaknesses in commonly used software could expose public websites to unauthorised access.
More Than 10,000 Public Entities Were Affected
One of the most concerning findings was the scale of the problem.
The researchers identified more than 10,000 affected public entities and approximately 250,000 websites with security flaws.
The scale makes the situation particularly important because public websites can contain information relating to government operations, public services and citizens.
A vulnerability on a single website may appear relatively minor. However, when the same vulnerable technology is deployed across thousands of websites, the overall risk can become much larger.
This is one of the key challenges facing Polish web security. A single outdated software component can potentially expose a large number of organisations at the same time.
Courts Among the Most Concerning Targets
The investigation reportedly uncovered vulnerabilities affecting a significant portion of Poland’s judiciary.
According to the researchers, one vulnerability potentially provided access to websites belonging to around two-thirds of Poland’s judiciary, representing approximately 245 courts.
The discovery is especially concerning because court websites are part of essential public infrastructure.
Security failures involving judicial systems can create risks ranging from website hijacking and disruption to unauthorised access to information.
The researchers said they reported their findings through official government channels, allowing authorities and relevant organisations to investigate and address the weaknesses.
Outdated Software Created Serious Risks
One of the major issues identified during the investigation involved outdated software.
The researchers found critical vulnerabilities in PAD CMS, a content management system used by public organisations in Poland.
According to the investigation, the software contained vulnerabilities that could allow unauthorised access to some websites without requiring a password.
The problem was made more serious by the fact that the software was reportedly considered end-of-life, meaning it was no longer actively supported.
Using unsupported software creates a major challenge for Polish web security because newly discovered vulnerabilities may not receive security updates.
CERT Polska has published vulnerability reports involving widely used CMS software and coordinates responsible vulnerability disclosure in Poland.
Why Outdated CMS Software Is Dangerous
Content management systems make it easier for organisations to build and maintain websites, but they can become a security risk when they are no longer maintained.
Unsupported software may contain:
- Unpatched vulnerabilities
- Outdated libraries
- Weak authentication mechanisms
- Poor access controls
- Known security flaws
- Compatibility problems with modern security tools
The issue is not limited to Poland.
Public organisations worldwide rely on content management systems, plugins and third-party software. When these components are not regularly updated, attackers can potentially exploit known weaknesses.
The recent findings therefore provide another warning about the importance of Polish web security and software maintenance.
A Major Problem With Vulnerability Reporting
The researchers also highlighted problems beyond the technical vulnerabilities themselves.
They said some vendors did not have effective bug bounty programmes or straightforward ways for security researchers to report vulnerabilities.
That can create a dangerous situation.
A researcher may discover a vulnerability but have difficulty contacting the software provider or organisation responsible for the affected website.
In some cases, the researchers said their reports were treated as inconveniences rather than urgent security warnings.
Effective vulnerability disclosure is an important part of modern cybersecurity. Organisations need clear channels that allow researchers to report security weaknesses before criminals discover and exploit them.
What Could Happen If Public Websites Are Compromised?
The risks associated with vulnerable public websites can vary depending on the specific flaw.
Potential consequences include:
Website Hijacking
Attackers could potentially take control of vulnerable websites and replace legitimate content with malicious or misleading information.
Data Exposure
Some vulnerabilities can potentially expose information that should only be accessible to authorised users.
Service Disruption
Cyberattacks can make public websites unavailable, preventing citizens from accessing important online services.
Reputation Damage
A successful attack against a government institution can undermine public confidence in digital services.
Larger Cyberattacks
Compromised public websites can sometimes become an entry point for broader attacks against connected systems.
This is why Polish web Security is particularly important for organisations that provide essential public services.
Poland Faces Growing Cybersecurity Pressure
The discoveries come at a difficult time for Poland.
The country has been working to strengthen its cyber defences amid increasing concerns about cyberattacks targeting critical infrastructure.
Energy, water, transportation and government systems are particularly important because disruption to these services can affect large numbers of people.
Poland’s official cybersecurity infrastructure provides information and guidance for citizens, businesses and organisations operating within the country’s national cybersecurity system.
The Healthcare and Airport Risk
Hospitals and airports are among the most sensitive organisations in any country’s digital infrastructure.
Hospitals increasingly depend on digital systems for appointments, patient information, communication and operational management.
Airports similarly rely on technology for passenger services, websites, communications and operational processes.
A vulnerable public-facing website does not necessarily mean an attacker can immediately compromise an organisation’s internal systems. However, exposed websites can still create security and reputational risks.
The discovery of vulnerabilities across such a broad range of institutions shows why Polish web security needs continuous monitoring rather than one-time security checks.
What Organisations Can Learn From the Findings
The Polish investigation offers several important cybersecurity lessons for public institutions.
1. Keep Software Updated
Organisations should regularly update CMS platforms, plugins, frameworks and server software.
2. Remove End-of-Life Software
Unsupported applications should be replaced or isolated because they may no longer receive critical security patches.
3. Create Security Reporting Channels
Researchers need clear and reliable ways to report vulnerabilities.
4. Conduct Regular Security Audits
Public-facing websites should be tested regularly for known and newly discovered vulnerabilities.
5. Monitor Third-Party Components
An organisation may secure its own code while still being exposed through an outdated third-party component.
6. Respond Quickly to Security Reports
A vulnerability report should be treated as a potential security incident, not simply as an inconvenience.
Why Responsible Disclosure Matters
The Polish researchers ultimately reported their discoveries to government authorities through official channels.
This approach is an example of responsible vulnerability disclosure, where researchers alert affected organisations so they have an opportunity to investigate and fix a security problem.
Poland’s CERT Polska also maintains a coordinated vulnerability disclosure process for security reports.
CERT Polska vulnerability disclosure process
Responsible disclosure can help organisations fix vulnerabilities before they become widely exploited.
Polish Web Security Needs Continuous Attention
The scale of the research demonstrates why cybersecurity cannot be treated as a one-time project.
Public websites constantly change. New software is installed, developers modify code, plugins become outdated and new vulnerabilities are discovered.
That means Polish web security requires continuous monitoring, regular patching and effective communication between researchers, software developers and public institutions.
The discovery of vulnerabilities affecting courts, hospitals, airports and government websites also demonstrates how a relatively small software weakness can potentially have a much wider impact when the same technology is used across a large number of organisations.
Final Thoughts
The discovery of widespread vulnerabilities across Poland’s public web infrastructure has highlighted serious concerns about Polish web security.
Researchers Robert Kruczek and Kamil Szczurowski identified vulnerabilities affecting thousands of public entities and hundreds of thousands of websites, including systems connected to courts, hospitals, airports and government offices.
The findings underline the importance of keeping software updated, removing unsupported systems, improving vulnerability reporting and conducting regular security assessments.
For Poland and other countries building increasingly digital public services, strong cybersecurity is no longer optional. It is essential for protecting public institutions, maintaining trust and ensuring that critical online services remain available and secure.



