Poland’s public websites found vulnerable across 250,000 pages, researchers warn
Researchers uncovered security flaws in 250,000+ pages across 10,000 Polish public entities, exposing airports, hospitals and courts to major potential hacks.
Two Polish security researchers presented findings at Def Con showing that Poland’s public websites contain widespread, easily exploitable vulnerabilities. The team identified more than 10,000 affected public entities and roughly 250,000 websites or pages with security flaws, including critical services such as airports, hospitals and local government portals. Their work highlights systemic problems in software maintenance, vendor support and the mechanisms for reporting and fixing defects.
Scale of the discovery
The researchers said their scan uncovered vulnerabilities across municipal, regional and national online services, totaling hundreds of thousands of pages. Many of the affected sites belonged to public institutions that provide essential civic and infrastructure services. The breadth of the findings suggests the issue is not isolated to a few organizations but reflects broader weaknesses in how public web systems are managed.
Pad CMS vulnerability exposed hundreds of public sites
Among the most serious problems, the team identified a critical flaw in a widely used content management system known as Pad CMS. That vulnerability allowed authenticated access without a password to more than 300 public websites, the researchers reported. Investigators found the CMS had reached end-of-life status and was no longer supported by its developer, leaving unpatched installations scattered across government and institutional servers.
Judiciary sites compromised by another flaw
The duo also disclosed a separate vulnerability that impacted a large portion of Poland’s judicial websites, affecting roughly two-thirds of courts they examined. Exploitation of that bug granted access to content and administration panels on about 245 court sites, according to the researchers’ presentation. Given the sensitivity of judiciary data and case information, those exposures raise particular concern for legal integrity and privacy.
Vendor support and reporting channels found lacking
A recurring theme in the presentation was the absence of effective vendor maintenance and formal reporting mechanisms such as bug bounties or coordinated disclosure pathways. Researchers said some vendors dismissed submitted bug reports as minor inconveniences rather than security emergencies, slowing remediation. The lack of clear, mandatory routes for reporting defects and the prevalence of unsupported software versions both contribute to prolonged exposure.
Government notified; accountability and remediation uneven
The researchers reported their findings to government channels and indicated they engaged with multiple official bodies to prompt fixes. Responses, they said, varied from prompt patching in a few cases to limited action where vendors or administrators claimed resource constraints. The uneven remediation highlights gaps between detection and patch deployment across the public sector, leaving many services at continued risk until fixes are enforced.
Context of recent targeted attacks and national security implications
Poland has faced a recent string of suspected nation-state intrusions targeting critical infrastructure such as energy and water systems, making public-facing web vulnerabilities a strategic concern. Security experts say that weak public websites can serve as entry points or reconnaissance targets for more sophisticated campaigns that aim to disrupt essential services. The researchers framed their work as patriotic and preventive, arguing that discovering and reporting flaws reduces the attack surface available to hostile actors.
The researchers emphasized that many of the discovered bugs were straightforward to exploit, underscoring the mismatch between the technical ease of attack and the often sluggish institutional response. They also noted that automated scanning and widely available exploit techniques mean attackers do not need advanced capabilities to take advantage of these weaknesses. As a result, the discovery of mass vulnerabilities on Poland’s public websites should prompt accelerated inventory, hardening and patching efforts.
Broad remediation will require coordinated action between government IT units, independent security researchers and software vendors to prioritize patches and replace unsupported systems. Establishing mandatory disclosure channels, incentivizing bug reporting through bounties or legal protections, and conducting regular third-party audits could reduce future exposure. The researchers recommended immediate audits of mission-critical portals and sunset plans for end-of-life software still in production use.
Poland’s public websites now face scrutiny not only from defenders but from anyone seeking weak points, and the window for quick remediation is limited. The researchers concluded that their disclosures made the country "a little bit more safe" by forcing attention onto neglected systems, but they warned that sustained investment and policy changes are necessary to prevent similar findings in future.