More than 36,000 internet-facing instances of Plex Media Server unpatched flaws are sitting wide open to attack, with no CVE identifiers assigned yet and no easy way for the broader security community to track the vulnerabilities. That last part is the uncomfortable operational reality: no CVE means most automated scanners, vulnerability-management dashboards and enterprise patch-prioritisation tools are functionally blind to the risk.

Plex issued its warning roughly a week before this writing, urging all server owners and desktop users to update immediately. The flaws affect Plex Media Server v1.43.2 and earlier. The company has asked users to upgrade to version 1.43.3, released on 19 May, and to update their Plex Desktop clients to version 1.115.0, released on 13 August, both available from the server management page or the official downloads page.

‘We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,’ Plex said in its advisory. ‘CVEs have been requested and we’ll reply to this thread with more details once they’re published.’

Shadowserver flags Plex Media Server unpatched flaws with daily scans

Nonprofit security organisation Shadowserver stepped in on Friday to quantify the exposure. According to SC Media, Shadowserver has been scanning and identifying these unpatched servers daily since 4 September 2026, acting on Plex’s advisory for v1.43.2 and earlier. ‘Over 36K instances found still unpatched,’ Shadowserver said. ‘No CVEs have been issued meaning the vulnerabilities are invisible to the security community limiting an effective response.’

That framing matters. Without CVE identifiers, vulnerability-management programmes at organisations running Plex in a self-hosted capacity cannot automatically flag the exposure for remediation. Security teams that rely on feed-based alerting will not see the issue at all unless they are actively monitoring Plex’s own advisory thread.

Plex has not released technical details of the current flaws, but the urgency is clear enough from the fact that the company took the unusual step of emailing customers directly about patching, one of a very limited number of occasions it has done so. Reverse-engineering a patch to develop a working exploit is a well-understood attacker technique, and with over 36,000 exposed servers still unpatched, the window is narrowing.

NAS users face additional delay from package-manager distribution

One group that may find patching harder than others is those running Plex on network-attached storage (NAS) devices. Plex itself flagged the issue in its advisory: ‘If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually.’ runZero has noted that automated package managers on NAS platforms can experience distribution delays, meaning relying on the platform’s own update mechanism rather than installing the package manually could leave a device exposed for longer than expected.

A familiar pattern of exploited Plex vulnerabilities

The current situation does not exist in isolation. In August 2025, Plex warned users to patch a high-severity vulnerability now tracked as CVE-2025-34158, which can be exploited to steal the server owner’s credentials.

Before that, the US Cybersecurity and Infrastructure Security Agency (CISA) flagged a Plex Media Server flaw, CVE-2020-5741, as actively exploited. According to Penligent, that vulnerability involved authenticated remote code execution through unsafe behaviour associated with the Camera Upload feature and server configuration, a specific technical path that gave attackers the ability to make the server execute malicious code once they had a valid login.

CVE-2020-5741’s real-world impact proved severe. It was likely used to compromise the computer of a LastPass senior DevOps engineer, triggering the August 2022 data breach in which threat actors stole credentials and compromised the LastPass corporate vault. That same month, Plex notified its own users of a separate data breach, warning them to reset passwords after attackers accessed a database containing emails, usernames, and encrypted credentials.

The throughline across all three incidents is credential access. Once attackers are operating with valid credentials, defences drop sharply: only 37% of attacker actions are blocked at that stage, according to figures cited in the Blue Report 2026, which analysed 338 million simulations run in customer production environments. For Plex server owners still running v1.43.2 or earlier, the manual upgrade to v1.43.3 remains the immediate priority.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version