Plex has advised users to promptly update their desktop clients and media servers to fix several security vulnerabilities. Currently, these vulnerabilities lack CVE IDs for tracking, and while Plex did not provide further details on Tuesday, they are known to impact Plex Media Server v1.43.2 and earlier versions. The company has also reached out via email to users running affected versions, urging them to make updates as soon as possible to mitigate these security issues. "We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address various security concerns. We recommend all server owners and Desktop users upgrade to the latest version immediately," Plex stated. "CVE requests have been submitted, and we will update this thread with more information once they are available. If you are using Plex Media Server on a NAS device, the updated version may not yet appear in your package manager, but you can install it manually." Users with affected versions should secure their systems without delay by updating to Plex Media Server version 1.43.3 (released on May 19) and Plex Desktop client version 1.115.0 (released on August 13).
These updates can be downloaded from the official downloads page or the server management page. Although Plex hasn't disclosed specific details about these vulnerabilities yet, users are encouraged to follow the company’s guidance and secure their systems before potential attackers reverse-engineer the patches to exploit them. Plex has addressed multiple critical security flaws in the past, but this is one of the few times it has directly emailed customers regarding a specific vulnerability. In August 2025, the company alerted users about a high-severity vulnerability tracked as CVE-2025-34158, which could allow attackers to steal server owners' credentials. Two years earlier, in March 2023, CISA flagged a remote code execution flaw in Plex Media Server (CVE-2020-5741) as actively exploited, enabling attackers to execute malicious code on the server.
While CISA did not provide details on the attacks exploiting CVE-2020-5741, they were likely connected to LastPass's disclosure about a breach where a senior DevOps engineer's computer was hacked in 2022 via a third-party media software RCE bug, allowing the installation of keylogging malware. This access led to the theft of the engineer's credentials and a compromise of the LastPass corporate vault, resulting in a significant data breach in August 2022 when LastPass's database backups were stolen. In the same month, Plex informed users of a data breach and advised them to reset their passwords after attackers accessed a database containing emails, usernames, and encrypted credentials.
Read more...
