VYPR
patchPublished Sep 4, 2026· 1 source

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex has released updates for its Media Server and Desktop app to address multiple undisclosed security vulnerabilities, urging users to update immediately as CVE identifiers are pending.

Plex is strongly advising its user base to update their Media Server and Desktop applications to the latest versions following the release of patches for several undisclosed security vulnerabilities. The company has issued updates for Plex Media Server to version 1.43.3 and for the Plex Desktop app to version 1.115.0. While Plex has not detailed the specific nature or impact of these newly patched flaws, it has confirmed that it has requested CVE identifiers for them, indicating their potential significance.

In an official announcement, Plex emphasized the urgency of the update, stating, "We recommend all server owners and Desktop users update to the latest version as soon as possible." The company also provided specific guidance for users running Plex Media Server on Network Attached Storage (NAS) devices, noting that while updated versions might not yet be available through their respective package managers, manual installation of the package is possible. This proactive communication aims to ensure widespread adoption of the security fixes.

This advisory follows a period where Plex has been actively addressing security concerns. In August 2025, the company patched a critical vulnerability, CVE-2025-34158, which carried a CVSS score of 8.5. This authentication bypass flaw resided in the '/myplex/account' endpoint, allowing authenticated non-owner users to access sensitive server owner details, including administrative access tokens. Furthermore, a subsequent API call to '/api/resources' could reveal other servers associated with the owner, potentially exposing the entire Plex infrastructure.

The broader landscape of Plex usage indicates a significant number of devices running the Media Server. Data from Censys reveals that over 360,000 devices expose the Plex Media Server web interface to the internet. While this figure does not imply that all these devices are vulnerable, it highlights the substantial attack surface that Plex users represent and underscores the importance of timely patching.

Plex Media Server has historically been a target for threat actors. In February 2021, a denial-of-service (DoS) vulnerability was addressed. This flaw allowed attackers to exploit UDP packet reflection to amplify DoS attacks against other servers. The fix, implemented in Plex Media Server v1.21.3.4014 and newer, restricted server responses to UDP requests originating from the local network (LAN) only, preventing exploitation over the public internet (WAN).

Perhaps most notably, a Plex Media Server vulnerability played a role in the August 2022 LastPass breach. Attackers reportedly compromised an employee's home computer through a vulnerability in Plex Media Server (CVE-2020-5741, CVSS score: 7.2) and subsequently deployed keylogger malware. This incident served as a stark reminder of how vulnerabilities in seemingly unrelated services can have cascading effects on widely used password managers and their users.

The current undisclosed vulnerabilities, while not yet detailed, are being treated with high priority by Plex. The company's call for immediate updates suggests that the potential impact could be severe, ranging from unauthorized access to data exfiltration or system compromise. Users are strongly encouraged to verify their Plex Media Server and Desktop app versions and apply the latest updates without delay to safeguard their systems and data.

As CVE details are pending, the exact technical mechanisms and exploit vectors remain unknown. However, given Plex's history and the nature of past vulnerabilities, potential impacts could include unauthorized access to media libraries, control over server settings, or even the use of compromised servers for malicious activities. The pending CVEs will likely shed more light on the specific risks associated with these newly patched flaws.

Synthesized by Vypr AI