Key Takeaways
- Two researchers scanning the Polish web found 250,000 public websites exposed — airports, hospitals, courts
- A single abandoned CMS let them walk into 300+ government sites without a password; the vendor called it "end of life" and walked away
- One flaw unlocked two-thirds of Poland's judiciary — 245 courts — and vendors dismissed reports as inconveniences
- This isn't technical debt; it's institutional neglect dressed up as obsolescence
Robert Kruczek and Kamil Szczurowski did not set out to embarrass their country. They scanned the Polish web out of patriotism — a word that sounds naive until you see the results. What they found at Def Con in Las Vegas should freeze every public-sector CIO in Europe: more than 10,000 public entities, 250,000 websites, riddled with holes. Airports. Hospitals. Government offices. The judiciary itself.
The scale is not the story. The causality is.
Start with Pad CMS. A content management system used across the Polish public sector. The researchers found a critical vulnerability that let them access over 300 public websites without a password. No credential stuffing. No phishing. No zero-day wizardry. Just a front door left wide open. When they reported it, the vendor shrugged. The software was "end of life." Unsupported. Unpatched. Unapologetic.
"End of life" is a product lifecycle term. It has become a liability shield. Vendors use it to wash their hands of code still running in production — code they sold, deployed, and profited from. The Polish state paid for that code. The Polish state runs on that code. But the vendor's support calendar expired, so the risk transferred entirely to the taxpayer. That is not how software liability should work. That is how it does work.
Then there is the judiciary bug. One flaw. Two-thirds of Poland's courts. Two hundred forty-five court websites accessible. The researchers did not name the vector in their talk, but they didn't need to. The number speaks: 245 is not a footprint. It is a beachhead. If you control the court's web presence, you control the registry of legal proceedings, the publication of judgments, the trust anchor of the justice system. A hostile actor does not need to alter a verdict. They only need to make the system doubt its own records.
The vendors' response is the tell. Multiple vendors described bug reports as "inconveniences." That word choice is revealing. An inconvenience is a meeting that runs long. A vulnerability that exposes hospitals and airports is a crisis. Calling it an inconvenience means the vendor has no process to triage, no metric for severity, no culture that treats public-sector risk as distinct from a typo on a marketing page. It means the procurement contracts did not require one.
Poland has no bug bounty program for public infrastructure. No unified vulnerability disclosure channel. The researchers reported through "various official channels" — plural, vague, bureaucratic. That phrase hides a maze. When the front door to 300 government sites is open, the reporting path should be a hotline. Instead it is a paperwork chase.
Context sharpens the picture. This research lands amid a wave of suspected Russian intrusions targeting Polish energy and water providers. Some of those intrusions exploited weak cybersecurity. The Kremlin does not need zero-days when the defense perimeter is made of "end of life" CMS instances and vendors who call critical bugs inconveniences. The threat actor does not need to be sophisticated. The attack surface does the work for them.
Kruczek and Szczurowski closed their talk by saying the hassle was worth it because Poland is "a little bit more safe." That is the measured optimism of people who know how far "a little bit" sits from "secure." They handed the government a map of its own minefield. The map is accurate. The mines are live. The next move belongs to ministers, not researchers.
The ministers face a choice. They can treat this as a patching exercise — hire contractors, run updates, tick boxes. Or they can treat it as a procurement crisis. Every "end of life" system running in a hospital or airport represents a contract that failed to mandate long-term security maintenance. Every vendor who dismisses a critical report as an inconvenience represents a supplier that should be disqualified from future tenders. Every missing bug bounty represents a policy vacuum that the state chose not to fill.
Poland is not unique. The same rot lives in every European capital. The difference is that two patriots with a scanner and a conference slot just lit the Polish instance on fire for everyone to see. The light does not fix the structure. But it removes the excuse of ignorance.
The researchers did their job. The vendors did not. The procurement officers did not. The ministers have not — yet. "A little bit more safe" is the floor. The ceiling is a public sector that treats software liability as non-negotiable, that funds maintenance like it funds electricity, that punishes vendors who abandon code in critical infrastructure. Until then, the airports and hospitals and courts remain exactly where Kruczek and Szczurowski found them: exposed, indexed, waiting.