Poland's Public Infrastructure Faces Mass Exposure as Researchers Map 250,000 Vulnerable Sites
A nationwide scan revealed critical flaws in court systems, hospitals, and airports, highlighting gaps in vendor accountability and disclosure channels across Eastern Europe's cyber frontline

A Patriotic Exercise Turns into a National Audit
Robert Kruczek and Kamil Szczurowski set out to answer a straightforward question: how vulnerable is Poland's public internet infrastructure? Their answer, delivered at Def Con in Las Vegas, was more alarming than either researcher anticipated. Across more than 10,000 public entities operating approximately 250,000 websites, the duo identified systemic security weaknesses that left airports, hospitals, judiciary systems, and government offices exposed to potential compromise.
What began as a civic exercise in understanding national cyber resilience quickly revealed a patchwork of outdated software, vendor negligence, and institutional barriers to responsible disclosure. At DailyTechWire, we've tracked similar infrastructure audits across Asia and emerging markets, but the scale of Poland's exposure and the variety of affected institutions stand out, particularly given the country's position on the front line of regional cyber conflict.
Legacy Software and End-of-Life Abandonware
Among the most critical findings was a set of vulnerabilities in Pad CMS, a content management system widely deployed across Polish public sector websites. Kruczek and Szczurowski discovered flaws that permitted unauthorized access to more than 300 sites without requiring authentication. The vendor's response proved equally troubling: the software had reached end-of-life status and would not receive patches, leaving agencies with a choice between costly migration or continued exposure.
This pattern of abandonment is not unique to Poland. Across Central and Eastern Europe, budget constraints and procurement inertia often lock public institutions into long-term relationships with software vendors that lack the resources or incentive to maintain legacy products. The researchers found that some vendors treated vulnerability reports as nuisances rather than urgent security intelligence, a dynamic that undermines coordinated disclosure and delays remediation.
The judiciary presented another worrisome case. A separate vulnerability granted the researchers potential access to systems serving approximately 245 courts, representing roughly two-thirds of Poland's judicial infrastructure. While the specifics of the flaw were not disclosed publicly, the breadth of exposure underscores how a single weakness in shared infrastructure can cascade across an entire sector.
The Disclosure Problem
Poland lacks a mature bug bounty ecosystem and formalized disclosure channels for independent researchers. Kruczek and Szczurowski reported their findings through various official routes, navigating a fragmented landscape of ministries, agencies, and vendors with inconsistent policies and response times. The absence of a central vulnerability disclosure program means researchers operate without clear legal safe harbor, and public entities often lack the internal capacity to triage and act on incoming reports.
This institutional gap is particularly acute in countries facing active threat campaigns. Poland has experienced a sustained wave of intrusions targeting energy and water utilities, widely attributed to Russian-aligned actors exploiting weak perimeter defenses and unpatched systems. The researchers' work illuminates the supply side of that vulnerability: not just sophisticated zero-day exploits, but mundane configuration errors and legacy code that remain unaddressed for years.
At DailyTechWire, we've observed a similar disclosure friction in Southeast Asia, where government agencies often treat security researchers with suspicion rather than as partners. Poland's experience suggests that Eastern Europe faces a comparable cultural and procedural barrier, one that becomes more dangerous as geopolitical tensions rise and adversaries actively probe critical infrastructure.
Vendor Accountability and Procurement Reform
The ease with which Kruczek and Szczurowski identified critical flaws raises uncomfortable questions about vendor selection and oversight. Public sector procurement in many European countries prioritizes cost and compliance over long-term security, creating incentives for vendors to underbid and underinvest in maintenance. When software reaches end-of-life, the cost of migration often falls entirely on the customer, leaving agencies trapped between budget constraints and operational risk.
Some of the vulnerabilities the researchers uncovered were described as trivial to exploit, requiring minimal technical sophistication. That accessibility amplifies the threat surface: not only state-sponsored groups but also opportunistic actors and cybercriminals can leverage these weaknesses for ransomware deployment, data theft, or service disruption. The judiciary vulnerabilities, in particular, raise the specter of evidence tampering or docket manipulation if exploited by motivated adversaries.
Poland's government has begun to prioritize cyber defense in response to recent incidents, but the researchers' findings suggest that remediation will require structural reforms beyond incident response. Mandatory security standards for public sector software, vendor liability clauses, and dedicated funding for legacy system replacement are all potential levers, though each carries political and budgetary trade-offs.
Regional Implications and the Eastern Flank
Poland's vulnerability landscape is emblematic of broader challenges facing NATO's eastern members. Estonia, Latvia, Lithuania, and Romania have all invested heavily in digital government services while confronting persistent reconnaissance and intrusion attempts from Russian and Belarusian threat groups. The balance between digital modernization and security hardening remains precarious, particularly for smaller member states with limited cybersecurity workforces.
Kruczek and Szczurowski framed their research as an act of patriotism, motivated by a desire to make Poland safer. Their work also serves as a template for similar audits in neighboring countries, where comparable infrastructure and procurement practices likely produce similar risk profiles. The researchers noted that despite bureaucratic friction and vendor pushback, the effort was ultimately worthwhile, contributing to incremental improvements in national security posture.
From a policy perspective, the findings argue for greater transparency in public sector cybersecurity. Publishing anonymized vulnerability statistics, establishing clear disclosure pathways, and incentivizing vendor cooperation through procurement criteria could all accelerate remediation cycles. Poland's experience also highlights the need for regional coordination: shared threat intelligence, joint procurement frameworks, and cross-border incident response protocols would help smaller states achieve economies of scale in defense.
Moving Beyond Awareness
The researchers emphasized that their scan represented only a snapshot, and that the true scope of Poland's public web vulnerability likely extends beyond their findings. As agencies rush to patch reported flaws, new systems come online, and vendors release updates, the attack surface continues to evolve. Continuous monitoring, automated vulnerability scanning, and red-team exercises will be necessary to maintain even baseline security hygiene.
At DailyTechWire, we see Kruczek and Szczurowski's work as a model for civic-minded security research in an era of escalating cyber conflict. Their willingness to navigate bureaucratic obstacles and document systemic failures provides a data-driven foundation for policy reform. Whether Poland's government and vendors will translate that foundation into sustained investment and accountability remains an open question, one with implications far beyond the country's borders.


