More than 36,000 Plex Media Servers exposed online are still running vulnerable versions of the software, leaving them open to potential attacks.

Plex warned users last week to secure their media servers as soon as possible after discovering several security issues. The company has not yet received CVE identifiers for the flaws, making them harder for the wider security community to track.

The vulnerabilities affect Plex Media Server version 1.43.2 and earlier. Plex has not disclosed technical details about the security issues, but users running affected versions are being urged to update immediately.

Plex released Media Server version 1.43.3 on May 19 to address the security problems. Plex Desktop users should also upgrade to version 1.115.0, which was released on August 13. Both updates are available through the server management page or Plex’s official download page.

“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address several security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,” Plex said.

Plex also noted that CVEs have been requested and that more information will be shared once they are published. Users running Plex on NAS devices may find that the updated package is not yet available through their device’s package manager, although the update can be installed manually.

The warning comes after Shadowserver reported that more than 36,000 Plex Media Server instances exposed to the internet were still running vulnerable versions. The nonprofit security organization said it has been scanning and reporting unpatched Plex installations daily since September 4 in response to Plex’s security advisory.

READ
PostgreSQL Fixes Critical Flaw Allowing Replication Users to Run Code

Shadowserver also pointed out that the lack of CVE identifiers makes the vulnerabilities effectively invisible to much of the security community, limiting the ability to respond effectively.

Although Plex has not revealed what the vulnerabilities can be used for, users are being advised to update before attackers have an opportunity to reverse-engineer the patches and develop working exploits. Plex’s decision to directly email customers about updating highlights the urgency of the situation.

Plex has faced serious security issues before. In August 2025, the company warned users about a high-severity vulnerability that could be exploited to steal server owners’ credentials. Another Plex remote code execution flaw, tracked as CVE-2020-5741, was previously listed by CISA as actively exploited.


Buy ExpressVPN with PayPal or Credit Card

That vulnerability was linked to an attack believed to have compromised the computer of a LastPass senior DevOps engineer and contributed to the major data breach in 2022. Plex itself also disclosed a data breach that same year and advised users to reset their passwords after attackers accessed a database containing email addresses, usernames and encrypted credentials.

Advertisement