Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Ravie LakshmananSep 04, 2026Vulnerability / Network Security

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Ravie LakshmananSep 04, 2026Vulnerability / Network Security

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.

“We recommend all server owners and Desktop users update to the latest version as soon as possible,” Plex said in an announcement this week. “If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet, but you can install the package manually.”

In August 2025, Plex addressed a high-severity security flaw (CVE-2025-34158, CVSS score: 8.5), an authentication bug that stemmed from the “/myplex/account” endpoint incorrectly exposing the server owner’s account details, including their administrative access token, even when accessed by any authenticated non-owner or lower-privileged user.

Additionally, a subsequent “/api/resources” API call can be used to reveal other servers accessible by that server owner, potentially exposing the owner’s entire Plex infrastructure to unauthorized access. The combination of the two API calls creates an exploit chain that can lead to infrastructure discovery.

Data from Censys shows that there are more than 360,000 devices exposing the Plex Media Server web interface, although it’s worth noting that not all of them are vulnerable.

Vulnerabilities in Plex Media Server have been exploited by threat actors from time to time. In February 2021, Plex released a security update to resolve an issue that allowed attackers to cause an affected server to “reflect” UDP packets in order to increase the volume of a denial-of-service (DoS) attack against another server.

The hotfix (Plex Media Server v1.21.3.4014 or newer) ensures that the server will only respond to UDP requests from the local network (LAN) and not the public internet (WAN).

Notably, the August 2022 breach of LastPass was driven by attackers implanting keylogger malware on an employee’s home computer after compromising it through a Plex Media Server vulnerability (CVE-2020-5741, CVSS score: 7.2).

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.