Plex warns users to patch security vulnerabilities immediately

by · BleepingComputer

Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities.

These flaws have not yet been assigned CVE IDs for easy tracking, and while Plex didn't provide additional details on Tuesday, the security issues are known to affect Plex Media Server v1.43.2 and earlier.

Plex also emailed users running affected versions and asked them to update as soon as possible to address these security flaws.

"We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible," the company said

"CVEs have been requested and we'll reply to this thread with more details once they're published. If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually."

Those running affected versions are advised to secure their systems as soon as possible by updating Plex Media Server to version 1.43.3 (released on May 19) and the Plex Desktop client to 1.115.0 (released on August 13), which can be downloaded from the official downloads page or the server management page.

Plex email (Jedi-Master_Kenobi)

​​Although Plex hasn't shared any details about these vulnerabilities so far, users should follow the company's advice and secure their systems before attackers reverse-engineer the patches and develop an exploit.

While Plex has patched multiple critical security flaws over the years, this is one of the few instances where it has also emailed customers about upgrading their systems to address a specific vulnerability.

In August 2025, the company also warned users to patch a high-severity vulnerability tracked as CVE-2025-34158 that allows threat actors to steal the server owner's credentials.

Two years earlier, in March 2023, CISA flagged a Plex Media Server remote code execution flaw (CVE-2020-5741) as actively exploited, which can allow attackers to make the server execute malicious code

While CISA didn't share details on the attacks exploiting CVE-2020-5741, they were likely linked to LastPass's disclosure that one of its senior DevOps engineers' computers had been hacked in 2022 using a third-party media software RCE bug to install keylogging malware.

The attackers used this access to steal the engineer's credentials and compromise the LastPass corporate vault, leading to a massive August 2022 data breach after they stole LastPass's database backups.

The same month, Plex notified users of a data breach and warned them to reset passwords after attackers gained access to a database containing emails, usernames, and encrypted credentials.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report