← All stories
● Covered by 2 sources · 3 reportsMedium impact1 negative2 neutral

Plex urges users to update desktop clients and media servers for security patches

🔄 Updated 23d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Plex released Media Server 1.43.3 and Desktop 1.115.0 to fix security flaws.
  • Plex Media Server v1.43.2 and earlier are affected.
  • Plex emailed users running affected versions to update.
  • CVE IDs for these vulnerabilities are pending.
  • Plex vulnerabilities have been exploited in the past.
  • Plex Media Server on NAS devices may require manual package installation.
  • Plex addressed CVE-2025-34158 (CVSS 8.5) in August 2025.
  • CVE-2025-34158 was an authentication bug exposing server owner's account details.
  • The /myplex/account endpoint incorrectly exposed administrative access tokens.
  • The /api/resources API call could reveal other servers accessible by the owner.
  • 36,000+ Plex Media Servers remain unpatched.
  • Plex Media Server 1.43.3 was released on May 19.
  • Plex Desktop 1.115.0 was released on August 13.

Immediate Security Updates Released

Plex has issued an urgent recommendation for users to update their Plex Media Server and Plex Desktop clients. The company released Plex Media Server version 1.43.3 on May 19 and Plex Desktop version 1.115.0 on August 13 to address several undisclosed security vulnerabilities. These updates are available for download from the official Plex website or through the server management page.

Vulnerabilities Affect Older Versions

The security flaws are known to impact Plex Media Server v1.43.2 and earlier versions. While specific details about the vulnerabilities have not been disclosed, Plex has confirmed that CVE IDs have been requested and will be published once available. Users running Plex Media Server on NAS devices may need to manually install the updated package if it is not yet available through their package manager.

Unusual Communication Indicates Severity

Plex's decision to email users directly about these updates is notable, as it is an infrequent action for the company, suggesting the critical nature of the vulnerabilities. This proactive communication aims to ensure that users secure their systems before potential attackers can reverse-engineer the patches and develop exploits. Previous security incidents at Plex include a high-severity vulnerability in August 2025 (CVE-2025-34158) and an actively exploited remote code execution flaw in March 2023 (CVE-2020-5741).

Updates

🕒 2026-09-09 · new reporting from BleepingComputer
  • 36,000+ Plex Media Servers remain unpatched.
  • Plex Media Server 1.43.3 was released on May 19.
  • Plex Desktop 1.115.0 was released on August 13.
🕒 2026-09-04 · new reporting from The Hacker News
  • Plex vulnerabilities have been exploited in the past.
  • Plex Media Server on NAS devices may require manual package installation.
  • Plex addressed CVE-2025-34158 (CVSS 8.5) in August 2025.
  • CVE-2025-34158 was an authentication bug exposing server owner's account details.
  • The /myplex/account endpoint incorrectly exposed administrative access tokens.
  • The /api/resources API call could reveal other servers accessible by the owner.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Over 36,000 Plex Media Servers exposed online are still vulnerable to recently disclosed security flaws, despite Plex urging users to update their systems. These vulnerabilities affect Plex Media Server v1.43.2 and earlier, and Plex has not yet released CVE IDs for them, hindering broader security community response.

Plex released updates for Plex Media Server (1.43.3) and Plex Desktop (1.115.0) to address multiple undisclosed security flaws. Users are advised to update immediately to mitigate potential risks, as Plex vulnerabilities have been exploited in the past.

Plex has released updates for its Media Server and Desktop client to address multiple security vulnerabilities and is urging users to update immediately. These patches are critical as Plex has emailed affected users, a rare action, indicating the severity of the flaws.