TechNewsReel
Live

Security Flaws Exposed Across 250,000 Polish Public Websites

Researchers identify systemic vulnerabilities affecting hospitals, airports, and two-thirds of the national judiciary.

TechNewsReel Newsroom · August 8, 2026

Security researchers Robert Kruczek and Kamil Szczurowski have uncovered widespread vulnerabilities across Poland's public internet infrastructure, exposing thousands of state agencies to potential cyberattacks. The findings, presented at the Def Con cybersecurity conference in Las Vegas, reveal a systemic failure in the security of the nation's digital public services.

The researchers identified security flaws affecting more than 250,000 websites and over 10,000 public entities. The scope of the risk is extensive, spanning critical infrastructure including hospitals, airports, and various government offices. Among the most severe discoveries was a specific bug that granted unauthorized access to approximately 245 courts, representing roughly two-thirds of Poland's entire judiciary.

Software Obsolescence

A significant portion of the risk stems from the use of outdated software that is no longer supported by its creators. Researchers found that critical vulnerabilities in Pad CMS allowed password-less access to more than 300 public websites. When contacted regarding these flaws, the developer of Pad CMS declined to issue a patch, stating that the software has reached 'end of life' status. This reliance on legacy systems creates permanent backdoors for attackers that cannot be closed without a complete migration to new platforms.

Systemic Implications

The scale of these vulnerabilities highlights a critical gap in public sector software maintenance and a lack of formal mechanisms to identify and remediate flaws before they can be exploited. Because the affected entities include essential services like healthcare and transportation, the potential for disruption is high. The ability for external actors to gain access to judicial and administrative systems suggests a vulnerability to both data theft and state-level espionage.

Future Outlook

While the public disclosure of these flaws is a necessary first step toward remediation, the refusal of some vendors to patch legacy software leaves a significant number of sites exposed. The researchers noted that while the awareness of these issues makes the infrastructure "a little bit more safe," the underlying problem of software lifecycle management remains. Observers will now be watching to see if the Polish government mandates security audits or provides a centralized framework for updating the thousands of agencies still running obsolete code.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.