Plex has issued an urgent recommendation for users to update their Plex Media Server and Plex Desktop clients. The company released Plex Media Server version 1.43.3 on May 19 and Plex Desktop version 1.115.0 on August 13 to address several undisclosed security vulnerabilities. These updates are available for download from the official Plex website or through the server management page.
The security flaws are known to impact Plex Media Server v1.43.2 and earlier versions. While specific details about the vulnerabilities have not been disclosed, Plex has confirmed that CVE IDs have been requested and will be published once available. Users running Plex Media Server on NAS devices may need to manually install the updated package if it is not yet available through their package manager.
Plex's decision to email users directly about these updates is notable, as it is an infrequent action for the company, suggesting the critical nature of the vulnerabilities. This proactive communication aims to ensure that users secure their systems before potential attackers can reverse-engineer the patches and develop exploits. Previous security incidents at Plex include a high-severity vulnerability in August 2025 (CVE-2025-34158) and an actively exploited remote code execution flaw in March 2023 (CVE-2020-5741).
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Plex has released updates for its Media Server and Desktop client to address multiple security vulnerabilities and is urging users to update immediately. These patches are critical as Plex has emailed affected users, a rare action, indicating the severity of the flaws.