Bleepingcomputer
Plex Urges Immediate Updates to Address Critical Security Vulnerabilities
Article Content
Plex has issued an urgent call for users to update their desktop clients and media servers to patch multiple undisclosed security vulnerabilities affecting Plex Media Server v1.43.2 and earlier. The latest versions, Plex Media Server 1.43.3 and Plex Desktop 1.115.0, have been released to address these flaws, which have not yet received CVE IDs. Users running affected versions are advised to secure their systems promptly to prevent potential exploitation. In the past, Plex has faced significant vulnerabilities, including CVE-2025-34158, which exposed server owner credentials, and CVE-2020-5741, linked to a major data breach at LastPass. The company has communicated directly with users about the need to upgrade, emphasizing the urgency of the situation. The vulnerabilities are currently untracked by CVE identifiers, heightening the risk as attackers may reverse-engineer the patches. The update process may vary for users on NAS devices, who might need to install the updated package manually. Security experts recommend immediate action to mitigate risks associated with these vulnerabilities.
Key Points: • Plex has released updates to patch multiple critical vulnerabilities. • Affected versions include Plex Media Server v1.43.2 and earlier. • Users are urged to update immediately to prevent potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.