Polish web scan finds 250,000 vulnerable government, hospital and airport sites
At Def Con, two Polish researchers detailed security flaws across more than 10,000 public entities and 250,000 websites, including an unsupported CMS exposing courts, hospitals and airports.


Two Polish security researchers told the Def Con cybersecurity conference in Las Vegas on Friday, August 7, that a scan of Poland’s public web uncovered security flaws across more than 10,000 public entities and roughly 250,000 websites, including airports, hospitals and government offices. Robert Kruczek and Kamil Szczurowski said they took on the project out of a desire to understand how exposed their country’s public internet was and to make it safer.
Key facts
| Item | Detail |
|---|---|
| Researchers | Robert Kruczek and Kamil Szczurowski (Poland) |
| Scope of scan | More than 10,000 public entities, about 250,000 websites with security flaws |
| Most critical cases | End-of-life Pad CMS exposed 300+ sites; a separate bug affected about 245 courts |
| Event and date | Def Con cybersecurity conference, Las Vegas, August 7, 2026 |
What the scan found
Kruczek and Szczurowski said many of the weaknesses trace back to common points of failure: third-party software used to organize and display web content. Because the same tools are deployed across many institutions, a single flawed product can put hundreds of unrelated organizations at risk. The researchers also found that some bugs were trivially easy to exploit, yet vendors did not always take the reports seriously, with some describing them as inconveniences rather than security defects.
Pad CMS: an end-of-life weak point
The most striking case involved Pad CMS, a content management system that is no longer supported. The researchers said critical vulnerabilities allowed them to access more than 300 public websites without entering a password. The software developer did not patch the product because it had reached end of life, leaving every site still running it exposed unless operators migrate to a supported platform. For organizations inside and outside Poland, the case is a reminder that an abandoned product can act as a standing backdoor long after it stops receiving updates.
Courts, hospitals and airports
A separate vulnerability affected roughly two-thirds of Poland’s judiciary, or about 245 courts, the researchers said. Airports, hospitals and government offices were also among the affected entities. The presentation did not describe active exploitation of those systems; instead, the findings were reported to the government through official channels. The researchers said the exercise was ultimately worth the effort, and that Poland is now “a little bit more safe” as a result.
Vendors and disclosure gaps
The research also highlighted a structural reporting problem. Many of the affected institutions lack bug bounty programs and clear ways for external researchers to report flaws, which slows remediation and discourages further scrutiny. When vendors dismiss reports as inconveniences, public organizations that depend on those vendors have few options beyond waiting for a patch that may never arrive. The combination of unsupported software, slow vendor response and weak disclosure routes is what turns one bug into a national-scale exposure.
What developers and AI teams should take away
For teams running websites, automation stacks or AI agents that interact with public web infrastructure, the findings are a practical checklist. Track every CMS, plugin and library in production and note end-of-life dates before they become a problem. Assume an unsupported product will not be patched, and build a migration path before a vulnerability is published. Publish a security contact and a responsible-disclosure route so researchers do not have to guess who to notify. And when an AI agent or scraper is pointed at a public site, remember that an unpatched CMS can expose data to outsiders just as easily as it can to an automated tool.
The research also arrives at a sensitive moment for Poland’s cyber defenses, which have been tested by a wave of suspected Russian hacks targeting the country’s energy and water providers. Some of those attacks reportedly took advantage of weak cybersecurity, which makes the new findings a timing signal as well as a technical one: public-sector software hygiene has become a national-security issue, not just an IT chore.
Source: TechCrunch, “Security
Source
TechCrunch AI Publicacion original: 2026-08-07T21:00:08+00:00
Lena Walsh
Colaborador editorial.
