Plex urges users to update after patching serious security flaws

Plex has urged its estimated 42 million monthly active global users to immediately update Plex Media Server to version 1.43.3 and Plex Desktop to version 1.115.0 to patch multiple serious security vulnerabilities. While the streaming platform has not yet disclosed specific details about the flaws, it has formally requested Common Vulnerabilities and Exposures listings.

Plex Issues Urgent Update Warning Across Server and Desktop Apps

The self-hosted media platform issued a security bulletin and directly emailed affected users to deploy the newly released software versions as quickly as possible. The fixes are available in Plex Media Server 1.43.3 (released on May 19th) and Plex Desktop 1.115.0 (released on August 13th). Both updates can be downloaded from Plex’s official downloads page. We recommend all server owners and Desktop users update to the latest version as soon as possible, writes Plex in an announcement from earlier this week. It is unusual for the platform to email users recommending that they update as soon as possible, which suggests that the vulnerabilities are, at the very least, of some serious concern to users.

We recommend all server owners and Desktop users update to the latest version as soon as possible

Plex, official announcement

How Users Can Manually Install the Security Patches

While standard desktop applications on Windows and MacOS with automatic updates enabled should ensure that version 1.43.3 or newer is installed, server environments and specialized hardware require careful attention. Network-attached storage devices, commonly known as NAS units, present a distinct logistical hurdle for administrators. As detailed by security reporting, administrators running the media server on a NAS device may find that the updated package is not yet available in their package manager yet, but you can install the package manually. To manually update your Plex Server, the advisory instructed, go to our downloads page and download the most recent version. Users should access their NAS web interface, select the App Store and follow the path to manually install the security update using the install wizard. Linux users should download the .deb package for Ubuntu and run sudo dpkg -i plexmediaserver_1.19.4.2935-79e214ead_amd64.deb (replacing the last filename with the name of the package you downloaded) and .rpm package for Fedora or CentOS before using run sudo dnf install plexmediaserver-1.19.4.2935-79e214ead.x86_64.rpm (also replacing the last filename with the name of the package you downloaded.) Full instructions for all platforms can be found at the Plex advisory here.

A History of High-Severity Authentication and Remote Access Flaws

This security advisory arrives on the heels of several notable vulnerabilities that have tested the platform’s infrastructure over recent years. According to The Hacker News, in August 2025, Plex addressed a high-severity security flaw related to an authentication bug stemming from the '/myplex/account' endpoint incorrectly exposing the server owner's account details, including their administrative access token, even when accessed by any authenticated non-owner or lower-privileged user. Additional historical incidents include a previously exploited remote code execution flaw (CVE-2020-5741) in March 2023 linked to the LastPass breach, where a third-party media software vulnerability was used to install malware, as well as a data breach experienced by Plex itself in August 2022, leading to a recommendation for users to reset passwords.

Plex urges users to update after patching serious security flaws
Photo: Yahoo News Canada

Unresolved Questions Surrounding Zero-Day Exploitation Status

There is no word on whether the as-yet-unknown vulnerabilities have already been exploited in the wild or not, so-called zero-days. Plex has confirmed that it has requested Common Vulnerabilities and Exposures listings and will provide more details once they're published. Until those identifiers are assigned and published, server operators must rely on the immediate deployment of version 1.43.3 to safeguard their media libraries.

vulnerability_AdobeStock_212155328
Photo: SC Media
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Jimmie Åkesson: Pro-Russian Views Disqualify Staff From SD

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.