First half of 2026 summary

We analyzed the results of audits, penetration tests and security scans performed for Polish companies in the first half of 2026. The results show that despite growing awareness, basic errors still dominate and are the main cause of successful attacks.

Most common vulnerabilities

  • Outdated CMS systems and plugins — about 35% of tested sites ran versions with known vulnerabilities.
  • Weak or default passwords — still present in administrative systems and vendor panels.
  • Lack of multi-factor authentication (MFA) — especially on high-privilege accounts.
  • Open and unprotected APIs — allowing data access without proper authorization.
  • Cloud misconfigurations — public buckets, excessive permissions, missing logging.

Most exposed industries

The most serious vulnerabilities were found in e-commerce, B2B services and other industries we work with. Many of these organizations are rapidly adopting AI tools, which further expands the attack surface.

Conclusions

The most effective security investment remains a return to basics: regular updates, MFA, access management, network segmentation and continuous testing. Advanced AI tools cannot replace solid security hygiene.

Download the full report

The full report includes detailed statistics, case studies and recommendations for different industries. Contact us to receive a free copy.

Need support?

Contact the CHORS team to discuss a tailored solution for your business.

Get in touch