More than 36,000 internet-exposed Plex Media Server instances remain unpatched against multiple security vulnerabilities, potentially leaving them open to cyberattacks.
A week ago, Plex urged users to update their media servers immediately to address security issues that have not yet been assigned CVE identifiers, making them more difficult for security researchers and organizations to track.
Although Plex did not disclose technical details when it issued the alert, the vulnerabilities affect Plex Media Server version 1.43.2 and earlier.
Users running an affected version should upgrade to Plex Media Server 1.43.3 as soon as possible. Plex also recommends updating the Plex Desktop client to version 1.115.0. Updates can be installed through the server administration page or downloaded from the Plex Media Server forum, the Plex Desktop download page, and the official Plex download page.
“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We encourage all server owners and desktop users to update to the latest version as soon as possible,” Plex said.
“A CVE has been requested and we will reply to this thread with details as soon as they are available. If you are running Plex Media Server on a NAS device, the updated version may not yet be available in your package manager, but you can install the package manually.”
On Friday, nonprofit cybersecurity organization Shadowserver warned that more than 36,000 Plex Media Server instances exposed to the internet remain unpatched and potentially vulnerable to attacks.

“Starting September 4, 2026, we are daily scanning and reporting unpatched versions of Plex Media Server in response to advisories issued by Plex for v1.43.2 and earlier. There are still over 36,000 unpatched instances,” Shadowserver said.
Shadowserver also noted that the vulnerabilities have not yet been assigned CVE identifiers, leaving the security community with limited information about the flaws and reducing its ability to respond effectively.
Plex has not released technical details about the vulnerabilities. However, users should follow the company’s warning and update their servers before attackers can reverse-engineer the patches and develop exploits. Plex rarely sends urgent security update notices directly to customers, making the company’s recommendation especially important.
In August 2025, Plex also warned users to patch high-severity vulnerabilities, including CVE-2025-34158, which can be exploited to steal Plex server owner credentials.
CISA previously listed a remote code execution vulnerability in Plex Media Server, tracked as CVE-2020-5741, as actively exploited. The flaw could allow attackers to execute malicious code on vulnerable servers.
Cybersecurity agencies have not publicly shared details about attacks exploiting CVE-2020-5741. However, the vulnerability has been linked in reporting to the compromise of a senior DevOps engineer’s computer at LastPass, which contributed to the company’s major data breach in August 2022. Attackers subsequently stole credentials and accessed LastPass’ corporate vault.
That same month, Plex disclosed a data breach and urged users to reset their passwords after attackers accessed a database containing customer email addresses, usernames, and encrypted credentials.
The overall prevention score can hide what happens after initial access. When attackers use valid credentials, your defenses can drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



