Technology

Two Researchers Found Security Holes in 250,000 Polish Websites

Martin HollowayPublished 2h ago4 min readBased on 6 sources
Reading level
Two Researchers Found Security Holes in 250,000 Polish Websites

Two Polish security researchers, Robert Kruczek and Kamil Szczurowski, presented findings at Def Con in Las Vegas on August 7, 2026, showing that more than 10,000 public organizations and 250,000 websites in Poland have security flaws that hackers could exploit. The affected sites include airports, hospitals, courts, and government offices. TechCrunch

The researchers found a critical flaw in a piece of software called Pad CMS, which many organizations use to manage and display their website content. The flaw let anyone walk into over 300 public websites without needing a password or any login at all. The company behind Pad CMS never fixed the problem because the software was no longer being maintained or updated. TechCrunch

A separate flaw the researchers found exposed the websites of about 245 courts. That is roughly two-thirds of all the courts in Poland. Kruczek and Szczurowski reported what they found to the Polish government through several official channels. TechCrunch

The researchers said the problem came from a combination of faulty software and the fact that Poland has no formal system for people to report security flaws they find. Many organizations run bug bounty programs, which pay outside researchers to find and report security problems before criminals can take advantage of them. Poland's public services had no such programs, leaving them open to attacks. TechCrunch

The findings come at a time of real danger. Poland has been working to strengthen its cyber defenses after a wave of suspected Russian hacks targeted the country's energy and water providers. TechCrunch Russian hackers had previously attacked Polish hospitals and a city water supply, causing hospitals to suspend operations and stealing data. (Financial Times) In February 2026, the US cybersecurity agency CISA published an alert about a cyber incident affecting Poland's energy sector, pointing to gaps in the security of the specialized computers that run physical infrastructure like power grids. (CISA)

Polish law does not require organizations to run penetration tests, which are simulated attacks designed to find weaknesses before real attackers do. Some critical infrastructure operators do undergo regular security audits, but most public institutions do not. (ICLG) The political landscape adds another layer of difficulty: a Polish court previously blocked an investigation into the former government's use of Pegasus spyware. (The Record)

The broader context here is one of systemic rather than incidental failure. Running unsupported software on hundreds of public websites is not a simple mistake that a patch can fix, because the patches will never come. When two-thirds of a country's court websites can be reached through a single type of flaw, one attacker could potentially move across many institutions that have no coordinated way to respond to incidents.

Without a legal requirement to test for weaknesses, public organizations have no reason to go looking for the kind of problems that two researchers found on their own. The regular security audits that do exist cover only a subset of critical infrastructure. Courts, hospitals, and airports are left depending on whether software companies choose to help and whether independent researchers happen to find and report flaws.

In this author's view, the combination of unsupported software, no way to report security flaws, and no legal requirement to test for them creates a type of failure that is entirely predictable. Poland's efforts to improve its cyber defenses after the energy and water attacks address one part of the problem, but the Def Con findings make clear that the country's public websites remain largely unmonitored.

What Kruczek and Szczurowski showed is that a determined search, not an advanced hacking technique, was enough to uncover weaknesses on a national scale. The types of flaws they found are well known and are regularly fixed by organizations with mature security practices. The real risk lives in the gap between what security professionals already know and what organizations actually put into practice.