CRBC News
Security

Nationwide Scan Finds 250,000 Vulnerable Websites in Poland — Airports, Hospitals and Courts Exposed

Nationwide Scan Finds 250,000 Vulnerable Websites in Poland — Airports, Hospitals and Courts Exposed
CRACOW, POLAND - 2021/05/01: A Polish national flag is seen displayed on a tenement house, which on public holidays is a legal obligation for every property owner.Poland is a member of European Union since May 1st 2004. On the 17th anniversary of Poland's membership in the European Union both Polish and European Union flags have been seen displayed on buildings. Opponents of the government's policies marched through city streets with both Polish and EU flags. (Photo by Filip Radwanski/SOPA Images/LightRocket via Getty Images) | Image Credits:Filip Radwanski / SOPA Images / LightRocket / Getty Images

At Def Con, Polish researchers Robert Kruczek and Kamil Szczurowski revealed a nationwide scan that exposed major security gaps across public services. They found more than 10,000 affected public entities and roughly 250,000 vulnerable websites, including airports, hospitals and government sites. Critical Pad CMS flaws allowed access to 300+ sites without a password, and about 245 courts were reachable. The researchers reported the issues to authorities to help improve national cyber defenses.

Two Polish security researchers have revealed the results of a large-scale scan of their country's public web infrastructure, finding widespread vulnerabilities that put critical services at risk.

Key Findings

Speaking at the Def Con cybersecurity conference in Las Vegas, Robert Kruczek and Kamil Szczurowski said their scan identified more than 10,000 affected public entities and roughly 250,000 websites with security flaws. The affected sites include airports, hospitals, government offices and court systems.

The researchers discovered critical vulnerabilities in the widely used content management system Pad CMS, which allowed access to over 300 public websites without supplying a password. The Pad CMS vendor did not patch the flaw because the product had reached "end of life" and was no longer supported.

Another serious vulnerability enabled the researchers to access approximately 245 courts — about two-thirds of Poland's judiciary — raising alarms about the integrity and confidentiality of legal records and case-management systems.

Causes and Risk Factors

Kruczek and Szczurowski highlighted several root causes: buggy or unsupported third-party software, the absence of formal bug-bounty programs, and a lack of straightforward reporting channels for security issues. They also reported that some vendors downplayed or dismissed vulnerability reports as mere inconveniences instead of addressing security flaws promptly.

Context and Response

The findings come as Poland works to strengthen its cyber defenses following a series of suspected Russian intrusions that targeted energy and water providers — incidents in some cases enabled by weak cybersecurity. The researchers said they reported their discoveries to government authorities via multiple official channels.

"Despite the hassle of reporting and coordinating fixes, the work makes Poland a little bit more safe," the pair told the Def Con audience.

Implications: The scan underscores how unsupported software, limited reporting mechanisms, and vendor complacency can rapidly translate into national security and public-safety risks. It also demonstrates the value of proactive, ethical research and clear disclosure pathways to reduce attack surfaces across public services.

Help us improve.

Related Articles

Trending