Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Plex Media Server vulnerabilities prompt urgent patch push across desktop and server
    Technology

    Plex Media Server vulnerabilities prompt urgent patch push across desktop and server

    Gary BehanBy Gary Behan10/09/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Plex Media Server vulnerabilities
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Plex has urged all users to update immediately, warning that Plex Media Server vulnerabilities affect version 1.43.2 and earlier, with patched releases now available for both the server software and desktop client. The company has taken the unusual step of emailing customers directly to press the point home.

    The fixed versions are Plex Media Server 1.43.3, released on 19 May, and Plex Desktop 1.115.0, released on 13 August. Both can be downloaded from the official downloads page or the server management page. ‘We recommend all server owners and Desktop users update to the latest version as soon as possible,’ the company said.

    CVE identifiers have not yet been assigned to the newly disclosed flaws, which makes tracking them against other security tools harder than usual. Plex has said CVEs have been requested and will share further details once they are published. In the meantime, the company is staying tight-lipped about the technical specifics, a calculated silence, since publishing details before most users have patched tends to hand attackers a ready-made recipe.

    Plex Media Server vulnerabilities and the infrastructure exposure risk

    One reason to take these disclosures seriously: Plex has a history with high-impact flaws. In August 2025, the company warned users to patch a high-severity vulnerability tracked as CVE-2025-34158, which allows threat actors to steal a server owner’s credentials. According to The Hacker News, CVE-2025-34158 carries a CVSS score of 8.5, placing it firmly in the high-severity band.

    The attack chain around that flaw goes further than a single credential theft. The Hacker News also reported that a subsequent call to the /api/resources API endpoint can reveal other servers accessible by the same owner, potentially exposing an owner’s entire Plex infrastructure to unauthorised access. In other words, compromising one server could be the foothold for reaching every other server tied to that account.

    The scale of potential exposure is not abstract. More than 360,000 devices expose the Plex Media Server web interface publicly, according to The Hacker News, meaning a meaningful portion of the user base is reachable directly from the internet, without any additional network access required by an attacker.

    A pattern of serious flaws, and a notorious data breach

    The history here is worth laying out. In March 2023, CISA flagged a Plex Media Server remote code execution flaw, CVE-2020-5741, as actively exploited, a vulnerability that allows attackers to make the server execute malicious code. While CISA did not share details on the specific attacks exploiting that flaw, they were likely linked to LastPass’s disclosure that one of its senior DevOps engineers’ computers had been hacked in 2022 using a third-party media software RCE bug to install keylogging malware.

    The attackers used that access to steal the engineer’s credentials and compromise the LastPass corporate vault. The result was a large-scale data breach in August 2022, after the attackers made off with LastPass’s database backups. The same month, Plex itself notified users of a separate data breach and warned them to reset passwords after attackers accessed a database containing emails, usernames, and encrypted credentials.

    The current round of Plex Media Server vulnerabilities has no such confirmed exploitation yet, but the window between patch release and attacker reverse-engineering tends to be short. For users running Plex on a NAS device, Plex has flagged that the updated version may not yet be available through the device’s package manager; the package can be installed manually in the interim.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleTeams and Outlook ARM crash traced to August Patch Tuesday update
    Next Article KB5120998 mouse reset bug hits non-English Windows 11 systems only, Microsoft confirms
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    IDScan driver’s licence breach triggers wave of class action lawsuits

    11/09/2026

    Citrix NetScaler Auth Bypass CVE-2026-19490 Hit by Active Exploit Attempts

    11/09/2026

    Chrome V8 Zero-Day CVE-2026-85046 Scores 8.8 as Google Rushes Fix

    11/09/2026

    Hôpital Privé de la Loire GDPR fine hits €500,000 over 727,000-record breach

    10/09/2026

    KB5120998 mouse reset bug hits non-English Windows 11 systems only, Microsoft confirms

    10/09/2026

    Teams and Outlook ARM crash traced to August Patch Tuesday update

    09/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.