Plex Urges Immediate Updates for Critical Security Vulnerabilities
Plex has issued an urgent advisory for its users, recommending immediate updates for **Plex Media Server** and **Plex Desktop** clients. The company has identified multiple unpatched security vulnerabilities, prompting an email campaign to alert affected users and prevent potential exploitation.
Users of **Plex Media Server** and **Plex Desktop** are strongly advised to update their software without delay to address recently discovered security flaws.
### Urgent Patch Release
**Plex** released **Plex Media Server v1.43.3** and **Plex Desktop v1.115.0** to mitigate several undisclosed security issues. While **CVE** IDs have not yet been assigned, the company has confirmed that **Plex Media Server v1.43.2** and earlier versions are affected.
"We recently released **Plex Media Server 1.43.3** and **Plex Desktop 1.115.0** to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible," **Plex** stated in an official forum post and direct email to users.
### Updating Your Systems
Users should update their **Plex Media Server** to version 1.43.3 (released May 19) and the **Plex Desktop** client to 1.115.0 (released August 13). These updates are available for download from the [official Plex downloads page](https://www.plex.tv/media-server-downloads/) or through the server management interface.
For users running **Plex Media Server** on a **NAS** device, the updated version may not immediately appear in the device's package manager. In such cases, **Plex** advises manual installation of the package.
### Proactive Security Measures
Although **Plex** has not yet provided specific technical details regarding these vulnerabilities, the urgency of their communication suggests a high-risk scenario. Security experts often recommend applying patches promptly, even without full disclosure, to prevent threat actors from reverse-engineering the updates and developing exploits.
### A History of Vulnerabilities
This is not the first time **Plex** has grappled with significant security challenges. In August 2025 (sic, likely 2022, given context), the company warned users to patch **CVE-2025-34158**, a high-severity vulnerability that could allow attackers to steal server owner credentials.
More notably, in March 2023, the **Cybersecurity and Infrastructure Security Agency (CISA)** flagged **CVE-2020-5741**, a **Plex Media Server** remote code execution flaw, as actively exploited. This vulnerability allowed attackers to execute malicious code on affected servers.
These exploits were reportedly linked to the **LastPass** breach in 2022, where a senior **DevOps** engineer's computer was compromised via a third-party media software **RCE** bug. This led to the installation of keylogging malware, enabling attackers to steal credentials and compromise the **LastPass** corporate vault, resulting in a significant data breach.
In the same month, **Plex** itself experienced a data breach, notifying users to reset their passwords after attackers gained access to a database containing emails, usernames, and encrypted credentials.