Plex Urges Users to Install Security Updates for Media Server and Desktop Apps
Plex is urging users to immediately update their Plex Media Server installations and desktop clients after releasing patches for multiple security vulnerabilities.
The vulnerabilities have not yet been assigned CVE identifiers, and Plex has not disclosed technical details about the flaws. However, the company confirmed that Plex Media Server version 1.43.2 and earlier are affected.
In a security update posted Tuesday, Plex advised users to upgrade as soon as possible. The company also emailed customers running affected versions of its software.
“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We encourage all server owners and desktop users to update to the latest versions as soon as possible,” Plex said.
Plex added that a CVE has been requested and that additional information will be provided once it becomes available. Users running Plex Media Server on a network-attached storage device may need to wait for the updated package to appear in their NAS provider’s package manager. Plex said the update can also be installed manually.
Users should update Plex Media Server to version 1.43.3 and the Plex Desktop client to version 1.115.0. The server update was released on May 19, while the desktop client became available on August 13.
The latest Plex updates can be downloaded from the company’s official download page or through the Plex server management interface.
Plex has not released detailed information about the newly patched vulnerabilities. Updating promptly is still recommended because attackers could analyze the patches and develop exploits after technical details become public.
The media software company has addressed several serious security flaws in the past, but it rarely emails customers about updates tied to specific vulnerabilities. The direct warning highlights the importance of installing the latest Plex security updates.
In August 2025, Plex also warned users to patch a high-severity vulnerability tracked as CVE-2025-34158, which could allow an attacker to steal the Plex server owner’s credentials.
In March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) reported that attackers were actively exploiting a remote code execution vulnerability in Plex Media Server tracked as CVE-2020-5741. The flaw could allow attackers to execute malicious code on vulnerable servers.
CISA did not disclose details about the attacks exploiting CVE-2020-5741. However, the vulnerability may be related to a 2022 incident involving LastPass, in which attackers compromised the computer of a senior DevOps engineer by exploiting a remote code execution flaw in third-party media software and installing keylogging malware.
The attackers used the access to steal the engineer’s credentials, compromise LastPass’ corporate vault, and obtain database backups. The incident later contributed to a major data breach disclosed in August 2022.
That same month, Plex disclosed a separate data breach and asked users to reset their passwords after attackers accessed a database containing email addresses, usernames, and encrypted credentials.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



