Skip to main content
CybersecurityVulnerability Management

Plex Issues Urgent Patch for Multiple Undisclosed Flaws

Home media setup with NAS device in background and smartphone in foreground.

More than 360,000 devices expose the Plex Media Server web interface to the internet, according to Censys — a scale that Plex says makes prompt patching imperative after it released security updates this week.

Plex Media Server 1.43.3 and Plex Desktop 1.115.0 — update now, Plex says

Plex issued an announcement this week urging users to install updates that patch multiple, undisclosed security flaws. The fixes are included in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. "We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said.

The company added that CVE identifiers have been requested for the newly fixed issues and that it did not elaborate on the technical details of the vulnerabilities. For users running Plex Media Server on NAS devices, Plex warned that the updated package may not yet be available through third‑party package managers and recommended manual installation where necessary.

The August 2025 authentication bug and an exploit chain (CVE-2025-34158)

Plex has previously patched a high‑severity authentication flaw in August 2025: CVE-2025-34158, assigned a CVSS score of 8.5. That flaw stemmed from the "/myplex/account" endpoint incorrectly exposing the server owner's account details, including their administrative access token, even when accessed by any authenticated non‑owner or lower‑privileged user.

According to the record of that incident, a subsequent call to the "/api/resources" endpoint could then reveal other servers accessible by the server owner. The two API calls together formed an exploit chain that could enable an attacker to discover and map an owner's broader Plex infrastructure.

Censys visibility: more than 360,000 exposed web interfaces

Censys data cited by the report shows over 360,000 devices exposing the Plex Media Server web interface to the internet. The source notes, however, that not all exposed instances are necessarily vulnerable to the same flaws; exposure does not equate to confirmed vulnerability.

Historical exploits: UDP reflection hotfix (February 2021) and the August 2022 incident tied to CVE-2020-5741

Plex vulnerabilities have been weaponized in the past. In February 2021, Plex released a security update to stop an issue that allowed affected servers to "reflect" UDP packets and thereby amplify a denial‑of‑service attack against another server. The hotfix — Plex Media Server v1.21.3.4014 or newer — changed server behavior so it responds to UDP requests only from the local network (LAN) rather than the public internet (WAN).

Separately, the August 2022 breach of LastPass was described as being driven by attackers who implanted keylogger malware on an employee's home computer after compromising it through a Plex Media Server vulnerability, CVE-2020-5741, which carried a CVSS score of 7.2.

What this means for server owners, NAS administrators, and end users

  • Server owners and Desktop users: Plex's public advice is direct — update to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 as soon as possible. The company framed the update as urgent and said CVE identifiers for the new fixes have been requested.
  • NAS administrators: Plex warned that updated packages may not be available yet through NAS package managers; administrators who host Plex on NAS hardware were advised they can install the package manually to ensure they receive the fixes promptly.
  • End users and defenders: Past incidents show Plex vulnerabilities can be used in both infrastructure discovery and as a vector to reach individual machines. Those maintaining networks with exposed Plex interfaces will have to weigh the visibility reported by Censys against the need to apply the vendor fixes and, where appropriate, limit exposure.

Plex's prompt release of 1.43.3 and 1.115.0 places the immediate task squarely with operators: install the updates, check whether your NAS vendor has pushed the package, or apply the package manually if it has not. Plex has requested CVE identifiers for the newly patched issues but has not published technical details, leaving defenders to act on the vendor's update guidance and past lessons about how Plex vulnerabilities can be chained or repurposed. The public visibility reported by Censys — more than 360,000 exposed interfaces — underscores why Plex framed the update as an urgent corrective step.

Original reporting: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html