Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.
The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.
"We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said in an announcement this week. "If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet, but you can install the package manually."
In August 2025, Plex addressed a high-severity security flaw (CVE-2025-34158, CVSS score: 8.5), an authentication bug that stemmed from the "/myplex/account" endpoint incorrectly exposing the server owner's account details, including their administrative access token, even when accessed by any authenticated non-owner or lower-privileged user.
Additionally, a subsequent "/api/resources" API call can be used to reveal other servers accessible by that server owner, potentially exposing the owner's entire Plex infrastructure to unauthorized access. The combination of the two API calls creates an exploit chain that can lead to infrastructure discovery.
Data from Censys shows that there are more than 360,000 devices exposing the Plex Media Server web interface, although it's worth noting that not all of them are vulnerable.
Vulnerabilities in Plex Media Server have been exploited by threat actors from time to time. In February 2021, Plex released a security update to resolve an issue that allowed attackers to cause an affected server to "reflect" UDP packets in order to increase the volume of a denial-of-service (DoS) attack against another server.
The hotfix (Plex Media Server v1.21.3.4014 or newer) ensures that the server will only respond to UDP requests from the local network (LAN) and not the public internet (WAN).
Notably, the August 2022 breach of LastPass was driven by attackers implanting keylogger malware on an employee's home computer after compromising it through a Plex Media Server vulnerability (CVE-2020-5741, CVSS score: 7.2).
Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
At a glance
- Severity
- Lowfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- None named
- Threat actors & malware
- None named
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-04 07:35 UTC
- Priority
- 34/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-04 07:35 UTC
Related stories
- Hackers exploit new MikroTik RouterOS flaws to hijack routers
BleepingComputer · 2026-09-07
- ConnectWise warns of new ScreenConnect flaw without patch
BleepingComputer · 2026-09-07
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
The Hacker News · 2026-09-07
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
The Hacker News · 2026-09-07
- N-able patches max severity N-central flaw amid ongoing attacks
BleepingComputer · 2026-09-07