Plex has urged users to update their media servers and desktop applications immediately after releasing fixes for multiple security vulnerabilities.
The flaws have not yet been assigned CVE identification numbers, and Plex has not disclosed technical details. They affect Plex Media Server version 1.43.2 and earlier, prompting the company to contact users running vulnerable versions by email.
In a message to customers, Plex said: “We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible.”
Plex Media Server 1.43.3 was released on 19 May, while Plex Desktop 1.115.0 became available on 13 August. Both updates can be obtained through Plex’s official downloads page or the server management interface.
The company said security identifiers had been requested and that further information would be provided once they were published. It warned that users running Plex Media Server on network-attached storage devices might need to install the update manually if it had not yet appeared in their device manufacturer’s package manager.
Plex security update follows previous warnings
Although the nature and severity of the newly fixed vulnerabilities remain undisclosed, users have been advised not to delay installation. Security researchers can sometimes analyse software updates to identify the weaknesses they address, potentially allowing attackers to develop exploits before systems are patched.
The warning is one of the relatively rare occasions on which Plex has directly emailed customers about upgrading their systems in response to specific security issues.
In August 2025, Plex warned users about a high-severity vulnerability, tracked as CVE-2025-34158, which could allow attackers to steal credentials belonging to a server owner.
Earlier, the US Cybersecurity and Infrastructure Security Agency added a Plex Media Server remote-code execution flaw, CVE-2020-5741, to its catalogue of vulnerabilities known to have been exploited in the wild. The weakness could enable an attacker to make a vulnerable server run malicious code.
The vulnerability was also linked to reporting surrounding the 2022 compromise of a LastPass DevOps engineer’s computer, in which attackers allegedly used a third-party media software flaw to install keylogging malware. Plex separately disclosed a data breach that year and advised users to reset their passwords after attackers accessed a database containing email addresses, usernames and encrypted credentials.
