Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

LowThe Hacker News · info@thehackernews.com (The Hacker News)·

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.

"We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said in an announcement this week. "If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet, but you can install the package manually."

In August 2025, Plex addressed a high-severity security flaw (CVE-2025-34158, CVSS score: 8.5), an authentication bug that stemmed from the "/myplex/account" endpoint incorrectly exposing the server owner's account details, including their administrative access token, even when accessed by any authenticated non-owner or lower-privileged user.

Additionally, a subsequent "/api/resources" API call can be used to reveal other servers accessible by that server owner, potentially exposing the owner's entire Plex infrastructure to unauthorized access. The combination of the two API calls creates an exploit chain that can lead to infrastructure discovery.

Data from Censys shows that there are more than 360,000 devices exposing the Plex Media Server web interface, although it's worth noting that not all of them are vulnerable.

Vulnerabilities in Plex Media Server have been exploited by threat actors from time to time. In February 2021, Plex released a security update to resolve an issue that allowed attackers to cause an affected server to "reflect" UDP packets in order to increase the volume of a denial-of-service (DoS) attack against another server.

The hotfix (Plex Media Server v1.21.3.4014 or newer) ensures that the server will only respond to UDP requests from the local network (LAN) and not the public internet (WAN).

Notably, the August 2022 breach of LastPass was driven by attackers implanting keylogger malware on an employee's home computer after compromising it through a Plex Media Server vulnerability (CVE-2020-5741, CVSS score: 7.2).

Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).

At a glance

Severity
Lowfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
None named
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-04 07:35 UTC
Priority
34/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. The Hacker NewsEstablished SourceFirst reported

    2026-09-04 07:35 UTC

Related stories