Plex tells users to update now as it patches unspecified security flaws

The media server company emailed customers directly, a rare step, and is holding back details until CVE numbers are assigned.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style 16:9 image of a modern office desk with a monitor displaying a completely blank white application window, keyboard in soft focus
Share

Key points

  • Plex released Plex Media Server 1.43.3 on 19 May and Plex Desktop 1.115.0 on 13 August to fix multiple security bugs.
  • The company emailed affected users this week urging an immediate update, a step it rarely takes.
  • All Plex Media Server versions 1.43.2 and earlier are affected.
  • CVE tracking numbers have been requested but not yet published.
  • Users on network storage devices may need to install the update manually if their device's app store has not caught up.

Plex, the company behind the popular home media streaming software of the same name, has told users to update their software right away to fix a batch of security holes it is not yet describing in public.

The warning went out this week by email to people running affected versions, which is unusual. Plex normally posts a note and lets users find it. This time it wanted eyeballs on the message.

The fixes live in Plex Media Server 1.43.3, released on 19 May, and Plex Desktop 1.115.0, released on 13 August. Anything on Plex Media Server 1.43.2 or older is vulnerable.

What did Plex actually say?

Not much, and that is the point. Plex confirmed it patched "a number of security issues" and asked server owners and desktop users to move to the latest builds. It has requested CVE identifiers, meaning the standard reference numbers researchers use to track individual bugs, and says it will share details once those are published.

That silence is deliberate. Once a patch ships, skilled attackers can compare the old and new code to work out what was fixed and build an attack for it. The narrower the window between patch and public detail, the better for users who have already updated.

Who needs to do what?

If you run a Plex server at home to stream your films, shows or music to your TV, phone or tablet, open the server's web dashboard and update to 1.43.3 or later. If you use the Plex Desktop app on Windows or macOS, update it to 1.115.0 or later. Both are available from the official Plex downloads page.

One wrinkle, first reported by BleepingComputer: if your Plex server runs on a network-attached storage box (a small always-on device that holds your files and sits on your home network), the update may not have arrived in that device's built-in package manager yet. Plex says you can install it by hand in the meantime.

Product Fixed version Released
Plex Media Server 1.43.3 19 May 2025
Plex Desktop 1.115.0 13 August 2025
Plex Media Server 1.43.2 and earlier Vulnerable Update required

Should Plex users be worried?

Not panicked, but not casual either. Plex has form. In August 2025 it patched CVE-2025-34158, a high-severity flaw that let attackers steal a server owner's login details. Back in 2020, CVE-2020-5741 allowed remote code execution, meaning an attacker could make the server run their own commands. The US cyber agency CISA later flagged that one as being used in real attacks.

That 2020 bug matters because of what it led to. The password manager LastPass has said one of its senior engineers was hacked in 2022 through a flaw in third-party media software running on their home computer. Attackers planted keylogging malware, which is software that records every keystroke, stole the engineer's credentials, and eventually pulled off the massive LastPass breach later that year. A home media server sat at the start of that chain.

Also in August 2022, Plex itself disclosed a breach of a database containing emails, usernames and scrambled passwords, and told users to reset.

So: update now, use a unique password for your Plex account, and turn on two-factor authentication if you have not already. A media server is a small target until it is the way into something bigger.

© 2026 Threat Vectr