Plex is urging users to update their media servers and desktop apps as soon as possible. The company says its latest releases fix “a number of security issues.” Plex has yet to explain what exactly the flaws do, and neither have they clarified whether attackers have exploited them.
The flaw affects Plex Media Server 1.43.2 and older versions. Plex also wants desktop users to run version 1.115.0 or newer. Plex posted the warning on its community forum on September 1. It also emailed users who run affected versions.
Plex keeps the flaws secret for now
Plex has not released technical details about the vulnerabilities. According to the company, a request has been made for the CVE records for these vulnerabilities. These records help provide a standardized method for recording vulnerabilities.
Plex plans on adding more details to the security advisory once the CVE records are out. For now, users do not know the flaws’ severity or the exact steps an attacker might use against them.
That lack of detail makes the risk hard to measure. Still, Plex has made its recommendation clear: users should update without waiting for the technical details. The company specifically advises all Plex server owners and desktop users to move to the latest versions.
NAS owners may need to act manually
Plex users who run the server on a NAS device face another issue. The patched version may not appear in the NAS maker’s package manager right away. Plex says users can install the package manually if the update remains unavailable through their normal update system.
This matters because NAS devices are a popular way to host Plex Media Server. Many users leave these machines running around the clock and use Plex to stream media outside their homes.
Users should check their installed server version rather than assume the update completed. The safe target version is Plex Media Server 1.43.3 or higher. For desktop users, Plex Desktop 1.115.0 or higher is recommended.
Plex released the fixes before the warning
The timeline also deserves attention. Plex released Media Server 1.43.3 before publishing its September security warning. The company has now confirmed that the release contains security fixes, but it has not identified which changes address the vulnerabilities. That means users may have already installed the fix without knowing it contained security patches.
Plex Desktop 1.115.0 also arrived before the public warning. Plex now links that release to its security fixes as well. The company has not said whether the flaws affect internet-facing servers, local networks, desktop clients, or specific features. That information should become clearer once the CVE records appear.
Plex has patched serious flaws before
Plex has previously suffered some major security issues. They found CVE-2025-34158 in August last year. That bug scored 8.5 on CVSS scale. The bug involved the /myplex/account endpoint. It can be exploited by a lower-privileged authenticated user to extract sensitive details about the server owner, such as an admin access token.
In addition, researchers determined that the stolen token would help an attacker find other Plex servers associated with the same account. That could give an attacker a wider view of the victim’s Plex setup. Plex fixed that issue in 2025 and urged users to update. The company has an even more serious incident in its history.
CISA once flagged a Plex flaw as exploited
CVE-2020-5741’s a flaw found in Plex Media Server and could let anyone remotely run code. The flaw involves Plex’s Camera Upload feature. An attacker who has access to the server administrator’s Plex account could upload a specially crafted file. The server could then execute malicious code.
In March 2023, CISA added it to its known exploited vulnerabilities catalog i. This basically means, the agency has evidence that attackers were actively exploiting it in the wild.
This flaw made headlines too because of its ties to the 2022 LastPass breach. LastPass says hackers broke into a senior DevOps engineer’s home computer and got their hands on company information. Apparently, some security researchers later figured out that hackers initially got in using a bug in third-party media software.
Attackers exploited a flawed Lenovo-Dropbox authentication process to create fake accounts and access files without victims’ passwords. The flaw affected 5,000 Dropbox accounts between August 4 and 21, 2026, before the integration was disabled.
But there’s nothing that actually proves Plex itself is what led to the LastPass incident. That distinction matters when discussing the incident.
Users should update before more details emerge
Plex has not said that attackers currently exploit the newly fixed flaws. There is also no public CVE record or severity score for the issues yet. That could change once Plex publishes more information.
For now, users should not wait. Once researchers can study the patches, they may uncover how the flaws work. Attackers can study the same changes and develop exploits.
Plex therefore wants users to update before those details become public. What Plex Media Server are you running? Make sure it’s at least 1.43.3. Using a desktop? Update to 1.115.0 or newer.
Running Plex on a NAS? Check your device’s package manager. If you’re not seeing the updated version there yet, it’s probably time to just install it manually. The bottom line: Plex found several security issues and wants everyone to update right away, even though they haven’t shared exactly what those issues are.