Plex Urges Immediate Patching of Critical Security Vulnerabilities

Plex Urges Immediate Patching of Critical Security Vulnerabilities

First seen 3 Sep 2026, 15:21 UTC BleepingcomputerSqmagazinenvd.nist.gov 60.6

Article Content

Browse articles
ThreatCluster

Plex has issued an urgent advisory for users to update their desktop clients and media servers to address multiple unassigned security vulnerabilities affecting versions 1.43.2 and earlier. The latest updates, Plex Media Server 1.43.3 and Plex Desktop 1.115.0, were released to mitigate these issues. Users running affected versions have been directly notified via email to secure their systems promptly. The vulnerabilities could potentially be exploited if not patched, as attackers may reverse-engineer the updates. Previous vulnerabilities, including CVE-2025-34158 and CVE-2020-5741, have posed significant risks in the past, with the latter being flagged by CISA for active exploitation in early 2023. Plex has not yet provided specific details about the current vulnerabilities or their potential impact. Users are advised to manually install updates if they are using NAS devices that may not have the latest version available in their package manager.

Key Points: • Plex users must update to versions 1.43.3 and 1.115.0 to mitigate critical vulnerabilities. • The vulnerabilities are unassigned CVEs and could be exploited if not patched quickly. • Plex has a history of critical vulnerabilities, including CVE-2025-34158 and CVE-2020-5741.

Timeline

2023-03-10
CVE-2020-5741 added to CISA KEV
CISA flagged a remote code execution flaw in Plex Media Server as actively exploited.
BleepingComputer
2025-08-21
CVE-2025-34158 published
Plex disclosed a high-severity vulnerability allowing credential theft for server owners.
BleepingComputer
2026-09-03
Plex issues urgent patch advisory
Plex urged users to update to the latest versions to address multiple critical vulnerabilities.
BleepingComputer