Plex Releases Media Server and Desktop Security Updates

Plex is urging customers to update after releasing fixes for multiple undisclosed security flaws in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service said it has requested CVE identifiers for the issues, but did not disclose their technical nature, severity or potential impact.
The company’s immediate recommendation applies to all server owners and Desktop users. Administrators running Plex Media Server on network-attached storage devices may not yet see the new build in their vendor’s package manager. Plex said they can install the package manually when the repository-delivered update is unavailable.
Limited vulnerability details, clear update guidance
The absence of public technical details means administrators cannot reliably determine exposure by matching a disclosed attack condition. The actionable information is the fixed-version guidance: Plex Media Server should be updated to 1.43.3 and Plex Desktop to 1.115.0.
Censys data cited in the report shows more than 360,000 devices exposing the Plex Media Server web interface. That figure does not establish that every exposed instance is affected by the newly patched flaws, but it underlines the scale of publicly reachable Plex deployments that operators need to review.
Plex’s wording also distinguishes between the server and desktop components. Teams should not assume that patching a server automatically addresses software installed on user endpoints, or that a desktop update changes the version of a separately managed Media Server.
Why prior Plex flaws remain relevant
Plex has addressed serious security issues before. In August 2025, it fixed CVE-2025-34158, a high-severity authentication flaw with a CVSS score of 8.5. The issue involved the /myplex/account endpoint exposing a server owner’s account details, including an administrative access token, to authenticated non-owner or lower-privileged users.
A subsequent call to the /api/resources API could reveal other servers accessible to that owner. Together, the two calls could create an exploit chain for infrastructure discovery and unauthorized access to information about the owner’s Plex environment.
The source also notes that a Plex Media Server vulnerability, CVE-2020-5741 with a CVSS score of 7.2, was involved in the path to the August 2022 LastPass breach after attackers compromised an employee’s home computer and implanted keylogger malware. In February 2021, Plex issued a hotfix for a separate issue that could let attackers use an affected server to reflect UDP packets and amplify a denial-of-service attack; the fix limited responses to requests from the local network rather than the public internet.
Immediate operational steps
Businesses using Plex should identify Media Server and Desktop installations, verify that they run the specified fixed releases, and account for NAS systems whose package feeds lag behind Plex’s release. They should also review whether web interfaces need to be publicly exposed and ensure update ownership covers both centrally managed servers and employee-operated systems. With the current flaws still undisclosed, prompt version verification and controlled exposure are the practical business priorities.

