Plex has urged users to immediately update their desktop clients and media servers to patch multiple undisclosed security vulnerabilities. Affected versions include Plex Media Server v1.43.2 and earlier, prompting emergency emails to customers and manual update recommendations for network-attached storage device owners.
Plex Media Server
The underlying flaws are known to affect Plex Media Server version 1.43.2 and earlier. While the platform has patched several critical security flaws over the years, this alert stands out because the company bypassed standard waiting periods and reached out directly to customers before assigning CVE identifiers or publishing technical details. Sergiu Gatlan reported on September 3, 2026, that Plex urged users this week to update their desktop clients and media servers immediately. Required Version Updates and Manual Installation Challenges
Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0
The security updates involve two specific releases: Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0. According to published timelines, the server update originally launched on May 19, while the desktop client update followed on August 13. Users can download both direct fixes from the official downloads page or through the server management interface. However, users operating media servers on network-attached storage hardware face potential delays. If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet, but you can install the package manually, Plex, official advisory explained in forum communications. We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,
the company said. Security analysts point out that withholding specific bug details is a calculated defensive tradeoff. Releasing technical vulnerability breakdowns before the broader user base has successfully applied patches can inadvertently supply bad actors with the blueprint needed to engineer working exploits. Network Exposure and Historical Security Incidents

CVE-2025-34158
The urgency behind the recent alerts stems from how media servers operate within domestic network environments. Because Plex Media Server sits directly on home networks and often utilizes port-forwarding to enable remote streaming outside the home, an unpatched instance transforms from a simple entertainment tool into a potential network foothold. This incident arrives amid a broader pattern of credential and execution risks associated with self-hosted media software. In August 2025, the company issued warnings regarding a high-severity vulnerability tracked as CVE-2025-34158, which allowed threat actors to steal the server owner’s credentials. Furthermore, CISA flagged a remote code execution flaw—CVE-2020-5741—as actively exploited in March 2023. Investigators previously linked that 2020 remote code execution bug to a significant 2022 security breach involving LastPass. Attackers exploited a third-party media software remote code execution vulnerability to target a senior DevOps engineer’s computer, deployed keylogging malware, harvested credentials, and ultimately compromised internal company vaults. Expected Timeline and Unconfirmed Attack Surfaces
Plex officials confirmed that CVEs have been requested and promised additional technical disclosures as soon as the tracking identifiers are formally published. CVEs have been requested and we'll reply to this thread with more details once they're published,
the company stated. Until those details arrive, the exact attack vector and severity ratings remain unconfirmed by external researchers. For now, server administrators must rely on the company’s explicit warning to secure their configurations. Network operators running older, unpatched instances are advised to treat locally stored credentials with caution and apply the manual package updates without waiting for automated repository syncs.