Plex has urged all users to update immediately, warning that Plex Media Server vulnerabilities affect version 1.43.2 and earlier, with patched releases now available for both the server software and desktop client. The company has taken the unusual step of emailing customers directly to press the point home.
The fixed versions are Plex Media Server 1.43.3, released on 19 May, and Plex Desktop 1.115.0, released on 13 August. Both can be downloaded from the official downloads page or the server management page. ‘We recommend all server owners and Desktop users update to the latest version as soon as possible,’ the company said.
CVE identifiers have not yet been assigned to the newly disclosed flaws, which makes tracking them against other security tools harder than usual. Plex has said CVEs have been requested and will share further details once they are published. In the meantime, the company is staying tight-lipped about the technical specifics, a calculated silence, since publishing details before most users have patched tends to hand attackers a ready-made recipe.
Plex Media Server vulnerabilities and the infrastructure exposure risk
One reason to take these disclosures seriously: Plex has a history with high-impact flaws. In August 2025, the company warned users to patch a high-severity vulnerability tracked as CVE-2025-34158, which allows threat actors to steal a server owner’s credentials. According to The Hacker News, CVE-2025-34158 carries a CVSS score of 8.5, placing it firmly in the high-severity band.
The attack chain around that flaw goes further than a single credential theft. The Hacker News also reported that a subsequent call to the /api/resources API endpoint can reveal other servers accessible by the same owner, potentially exposing an owner’s entire Plex infrastructure to unauthorised access. In other words, compromising one server could be the foothold for reaching every other server tied to that account.
The scale of potential exposure is not abstract. More than 360,000 devices expose the Plex Media Server web interface publicly, according to The Hacker News, meaning a meaningful portion of the user base is reachable directly from the internet, without any additional network access required by an attacker.
A pattern of serious flaws, and a notorious data breach
The history here is worth laying out. In March 2023, CISA flagged a Plex Media Server remote code execution flaw, CVE-2020-5741, as actively exploited, a vulnerability that allows attackers to make the server execute malicious code. While CISA did not share details on the specific attacks exploiting that flaw, they were likely linked to LastPass’s disclosure that one of its senior DevOps engineers’ computers had been hacked in 2022 using a third-party media software RCE bug to install keylogging malware.
The attackers used that access to steal the engineer’s credentials and compromise the LastPass corporate vault. The result was a large-scale data breach in August 2022, after the attackers made off with LastPass’s database backups. The same month, Plex itself notified users of a separate data breach and warned them to reset passwords after attackers accessed a database containing emails, usernames, and encrypted credentials.
The current round of Plex Media Server vulnerabilities has no such confirmed exploitation yet, but the window between patch release and attacker reverse-engineering tends to be short. For users running Plex on a NAS device, Plex has flagged that the updated version may not yet be available through the device’s package manager; the package can be installed manually in the interim.

