Plex urges urgent patching
Plex warns users to update Media Server and Desktop clients to fix multiple undisclosed security flaws.
Plex has issued an urgent call for users of its media server and desktop software to apply the latest updates, warning that multiple security vulnerabilities affect earlier versions. While the company has so far withheld technical details — the flaws have not yet been assigned CVE identifiers — it is urging everyone running Plex Media Server v1.43.2 or earlier to upgrade without delay.
The warning, posted on the Plex forums on Tuesday and echoed in direct emails to affected users, marks an unusually forceful push from a company that has historically reserved such broad alerts for the most serious issues. Plex said it has already requested CVEs and will publish more specifics once those identifiers are assigned.
What Plex has confirmed
In its advisory, Plex stated that it recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. The company recommends all server owners and Desktop users update to the latest version as soon as possible. The updated server software was released on May 19, while the desktop client followed on August 13.
Plex also added a note for those running its software on NAS devices, saying the updated version may not yet be available through the device's package manager and that users can install the package manually instead.
No details yet, but risk is clear
Plex did not disclose the nature of the vulnerabilities, leaving users uncertain about the potential impact. The lack of assigned CVE IDs and the company's choice to email customers directly signal that this is not a routine patch cycle. History suggests that when a media server vendor like Plex withholds details initially, it often does so to give users a head start before attackers can reverse-engineer the fixes and build working exploits.
Users running affected versions are advised to update to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 immediately, either from the official downloads page or through the server management page.
Quote from Plex
"We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible."
The statement continues, "CVEs have been requested and we'll reply to this thread with more details once they're published. If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually."
A pattern of proactive patching
This is one of the few instances where Plex has gone beyond a forum post and emailed customers about upgrading their systems to address a specific vulnerability. The company has patched multiple critical security flaws over the years, but such direct outreach is rare.
In August 2025, Plex warned users to patch a high-severity vulnerability tracked as CVE-2025-34158, which could allow threat actors to steal the server owner's credentials.
Earlier incidents loom large
Plex's history with security incidents adds weight to its latest advisory. In March 2023, CISA flagged a Plex Media Server remote code execution flaw, CVE-2020-5741, as actively exploited. That flaw could allow attackers to make the server execute malicious code.
While CISA did not share details on the attacks exploiting CVE-2020-5741, they were likely linked to LastPass's disclosure that one of its senior DevOps engineers' computers had been hacked in 2022 using a third-party media software RCE bug to install keylogging malware. The attackers used that access to steal the engineer's credentials and compromise the LastPass corporate vault, leading to a massive August 2022 data breach after they stole LastPass's database backups.
The same month, a breach
The same month, Plex notified users of a data breach and warned them to reset passwords after attackers gained access to a database containing emails, usernames, and encrypted credentials.
Key numbers and facts
- Affected version: Plex Media Server v1.43.2 and earlier
- Patched server version: 1.43.3, released May 19
- Patched desktop version: 1.115.0, released August 13
- August 2025 advisory: CVE-2025-34158 (high-severity credential theft)
- March 2023 CISA flag: CVE-2020-5741 (actively exploited RCE)
Why this matters
For Plex users, the immediate takeaway is clear: apply the updates without waiting for more details. The company's decision to email customers and issue a public advisory before CVEs are published suggests it believes the risk is significant enough to warrant immediate action. Given the history of Plex vulnerabilities being exploited in the wild — and the cascading consequences seen in the LastPass incident, where a media software flaw became a stepping stone to a major breach — the stakes are high. Users who delay patching could find themselves exposed to attacks that have not yet been fully described, but which Plex evidently considers serious enough to break its usual silence.
Sources
- BleepingComputer Original source
- CVE-2025-34158 Also reporting
- warned users Also reporting
Continue Reading
ARM Windows users hit by Teams, Outlook launch failures
Microsoft confirms August 2026 updates break Teams and Outlook on ARM devices; workaround available.
Zero trust meets its agentic AI reckoning
Autonomous agents strain zero trust's identity limits, experts warn as adoption lags.
Sangoma Switchvox flaw exploited in active attacks
CVE-2026-9586, an unauthenticated SQL injection in Switchvox, is under active exploitation, Horizon3 reports.