More than 36,000 Plex Media Server installations exposed to the internet remain unpatched against multiple recently disclosed security vulnerabilities, leaving them at risk of attack.
The figure was identified by the Shadowserver Foundation, which monitors internet-connected systems and tracks vulnerable services. Its findings indicate that a large number of Plex servers have yet to receive the updates needed to address the flaws.
Plex Media Server is used to organise and stream films, television programmes, music and other media from computers and network-attached storage devices. While many installations are intended for private use, some are configured to allow remote access over the internet.
Those publicly reachable systems can provide attackers with a direct target when security weaknesses remain unresolved. The vulnerabilities affect outdated versions of the server software, meaning users who have not installed Plex’s available fixes may be exposed.
Security researchers disclosed the flaws recently, prompting Plex to issue updates for affected installations. The company’s software can be updated through the server’s administration settings, although the precise process varies depending on the operating system and how Plex was installed.
Users who expose their media libraries to the internet are advised to check that they are running the latest available Plex Media Server release. Anyone who does not require remote access can also reduce their exposure by disabling external connections or restricting access through their network settings.
The Shadowserver findings underline the continuing risk posed by internet-facing software that is left unpatched. Although the number identified represents only visible Plex servers, systems that are not publicly reachable may still require the same security updates.