Plex Urges Immediate Updates to Patch Undisclosed Security Flaws
Plex has released critical security updates for its Plex Media Server (v1.43.3) and Plex Desktop (v1.115.0) to address multiple vulnerabilities affecting versions 1.43.2 and earlier. While the flaws have not yet been assigned CVE identifiers, the company has proactively emailed users running affected versions, urging them to apply the patches immediately.
The updates were released on May 19 (server) and August 13 (desktop), with manual installation required for NAS devices if the latest version isn’t yet available in their package managers. Plex has stated that CVE details will be published once assigned, but no further information on the vulnerabilities’ severity or exploitability has been disclosed.
This is not the first time Plex has faced significant security risks. In August 2025, the company patched CVE-2025-34158, a high-severity flaw allowing credential theft. Additionally, in March 2023, CISA warned of active exploitation of CVE-2020-5741, a remote code execution (RCE) vulnerability in Plex Media Server. That flaw was later linked to the 2022 LastPass breach, where attackers compromised a senior DevOps engineer’s system via a third-party media software RCE bug, leading to the theft of corporate vault backups.
Plex also suffered a data breach in August 2022, exposing user emails, usernames, and encrypted credentials, prompting a mandatory password reset. With no exploit details currently available, users are advised to update to mitigate potential risks before attackers reverse-engineer the patches.
Plex, Inc. cybersecurity rating report: https://www.rankiteo.com/company/plex-inc
"id": "PLE1788442941",
"linkid": "plex-inc",
"type": "Vulnerability",
"date": "5/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Media Streaming',
'name': 'Plex',
'type': 'Company'}],
'customer_advisories': 'Users running affected versions have been emailed to '
'apply patches immediately.',
'date_publicly_disclosed': '2025-08-13',
'description': 'Plex has released critical security updates for its Plex '
'Media Server (v1.43.3) and Plex Desktop (v1.115.0) to address '
'multiple vulnerabilities affecting versions 1.43.2 and '
'earlier. The company has proactively emailed users running '
'affected versions, urging them to apply the patches '
'immediately. No CVE identifiers have been assigned yet, and '
'details on severity or exploitability remain undisclosed.',
'impact': {'systems_affected': 'Plex Media Server (v1.43.2 and earlier), Plex '
'Desktop (v1.114.0 and earlier)'},
'investigation_status': 'Ongoing (CVE details to be published once assigned)',
'recommendations': 'Users are advised to update to the latest versions of '
'Plex Media Server and Plex Desktop to mitigate potential '
'risks before attackers reverse-engineer the patches.',
'references': [{'source': 'Plex Security Advisory'}],
'response': {'communication_strategy': 'Proactive email notifications to '
'affected users',
'containment_measures': 'Security updates released for Plex '
'Media Server (v1.43.3) and Plex Desktop '
'(v1.115.0)',
'remediation_measures': 'Manual installation required for NAS '
'devices if the latest version isn’t '
'available in their package managers'},
'title': 'Plex Urges Immediate Updates to Patch Undisclosed Security Flaws',
'type': 'Vulnerability Disclosure'}