All news
cybersecurityregulation

10,000+ Polish Public Entities Exposed, Researchers Find

08 Aug 2026

Massive Security Gaps Uncovered in Poland's Public Sector

Security researchers Robert Kruczek and Kamil Szczurowski presented findings at Def Con in Las Vegas on Friday revealing widespread vulnerabilities across Poland's public digital infrastructure. Their research identified more than 10,000 affected public entities and 250,000 websites with security flaws—numbers that point to systemic weaknesses rather than isolated incidents.

What They Found

The scope of exposure spans multiple critical sectors:

  • Airports, hospitals, and government offices in Poland were found to carry security vulnerabilities.
  • A critical flaw in Pad CMS, a piece of software that had reached end-of-life status and was no longer supported, allowed researchers to access over 300 public websites without a password.
  • A separate bug gave researchers access to websites belonging to approximately 245 Polish courts—about two-thirds of the country's judiciary.
  • Poland's energy and water providers have reportedly been targeted by suspected Russian hacks, adding a geopolitical dimension to the infrastructure risk.

Why the Vulnerabilities Persist

According to the researchers, the root problem isn't just buggy code—it's the lack of infrastructure to catch and fix it. Public services often rely on vendor software that lacks bug bounty programs or formal vulnerability reporting mechanisms. In some cases, vendors reportedly dismissed bug reports as mere inconveniences, allowing known issues to persist. The Pad CMS vulnerability illustrates a related problem: software that has gone end-of-life and unsupported can continue exposing public websites indefinitely, since no one is responsible for patching it.

The Risks Ahead

The report flags several ongoing risks tied to these findings:

  • Public services remain vulnerable to hijacking and other attacks due to buggy vendor software and absent reporting channels.
  • Unpatched, end-of-life systems like Pad CMS could keep exposing websites with no fix in sight.
  • Critical infrastructure—courts, hospitals, airports—could face disruption if these vulnerabilities are exploited.
  • Energy and water providers may continue to be targeted by state-linked threat actors.

It's worth noting that the report does not confirm whether any of these vulnerabilities have actually been exploited by attackers, or whether Polish authorities and the affected vendors have begun responding to the findings. The specific vendors or software behind most of the flaws—aside from Pad CMS—also weren't disclosed.

Why Founders Should Care

This research points to a set of gaps that could plausibly translate into market opportunity for cybersecurity and public-sector-focused startups:

  • The sheer scale—10,000+ entities and 250,000 vulnerable sites—suggests there may be substantial, underserved demand for automated security scanning tools built specifically for public sector infrastructure.
  • Vendors treating bug reports as inconveniences hints at a possible opening for startups building structured vulnerability disclosure or bug bounty platforms tailored to government clients, where such programs appear to be largely absent.
  • The end-of-life Pad CMS problem is likely not unique to Poland; founders working on legacy system modernization or migration tools may find similar demand wherever public institutions still run unsupported software.
  • Suspected state-linked targeting of energy and water providers could indicate growing government and enterprise appetite for critical infrastructure security solutions, particularly in regions with comparable geopolitical exposure.

None of these signals guarantee near-term contracts or funding, but they do suggest a pattern: public sector cybersecurity remains a fragmented, underinvested space—one where founders with the right compliance and government-sales expertise may find room to build.

Caption: Security researchers Robert Kruczek and Kamil Szczurowski present Polish web vulnerability findings at Def Con in Las Vegas.

Sources