---
title: "Polish researchers expose thousands of vulnerable public websites"
publisher: "Stockmark.IT"
author: "Stockmark.IT Website"
published: "2026-08-10T06:32:16+00:00"
modified: "2026-08-10T06:32:16+00:00"
date: 2026-08-10
canonical: "https://stockmark.it/security-researchers-scanned-the-polish-web-and-found-courts-hospitals/"
category: "Business"
categories: ["Business", "Cyber Security"]
image: "https://i0.wp.com/stockmark.it/wp-content/uploads/2026/08/polish-researchers-expose-thousands-of-vulnerable-public.png?fit=1536%2C1024&quality=80&ssl=1"
format: "news"
language: "en-GB"
---

# Polish researchers expose thousands of vulnerable public websites

**Published:** August 10, 2026
**Author:** Stockmark.IT Website
**Categories:** Business, Cyber Security
**Featured image:** ![Polish researchers expose thousands of vulnerable public websites](https://i0.wp.com/stockmark.it/wp-content/uploads/2026/08/polish-researchers-expose-thousands-of-vulnerable-public.png?fit=1536%2C1024&quality=80&ssl=1)

---

Security researchers in Poland have identified widespread vulnerabilities affecting a vast number of the nation’s public agencies and digital services. The investigation was conducted by two experts who sought to assess their country’s exposure to potential cyberattacks, driven by patriotic concerns for national safety.

During a presentation at the Def Con cybersecurity conference held recently in Las Vegas, Robert Kruczek and Kamil Szczurowski revealed that they had discovered over 10,000 affected public entities. Their scan uncovered approximately 250,000 websites containing security flaws. The scope of the risk extends to critical infrastructure including airports, hospitals, government offices, and judicial institutions.

The duo found that many organisations rely on buggy software from vendors who fail to address these issues promptly. A significant factor contributing to this vulnerability is the absence of bug bounty programmes or accessible channels for reporting security flaws. Some vendors have dismissed such reports as mere inconveniences rather than critical threats requiring immediate remediation. This attitude allows easily exploitable bugs to persist, leaving public services open to hijacks and other malicious attacks.

The findings emerge at a time when Poland is actively strengthening its cyber defences following a series of suspected Russian hacks targeting energy and water providers in the region. These previous incidents were often facilitated by weak cybersecurity measures within targeted organisations.

Specifically, Kruczek and Szczurowski identified critical vulnerabilities in Pad CMS, a widely used content management system. This flaw enabled them to access more than 300 public websites without requiring authentication credentials. The software developer had ceased support for the platform as it reached end of life status, yet continued usage by government bodies persisted.

Another discovered bug granted researchers access to roughly two-thirds of Poland’s judiciary network, encompassing approximately 245 courts. Despite these severe risks being reported through various official channels, immediate fixes have not been universally implemented across all affected sectors.

The researchers concluded that their extensive work was ultimately worthwhile for the collective security posture of the nation.

---

**Original URL:** https://stockmark.it/security-researchers-scanned-the-polish-web-and-found-courts-hospitals/
*Created by [WP Markdown Endpoint](https://wpmarkdownendpoint.com/)*
