Plex is urging users to immediately update their desktop applications and media servers after releasing patches for multiple security vulnerabilities. The undisclosed flaws affect Plex Media Server version 1.43.2 and earlier, although CVE identification numbers and technical details have not yet been published.
The company released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address the security issues. Plex also emailed customers running vulnerable versions and advised them to upgrade as soon as possible. NAS users may need to download and install the updated package manually if it has not yet appeared in their device’s package manager.
Although Plex has not confirmed whether the vulnerabilities are being actively exploited, delaying installation could increase the risk of an attack. Cybercriminals may analyze the released patches, identify the underlying weaknesses and develop exploits targeting servers that remain unprotected.
Plex has addressed serious security vulnerabilities in the past, including a 2025 flaw that could expose server-owner credentials and an older remote code execution vulnerability later added to CISA’s catalog of exploited flaws. Plex users should install the latest updates, restrict unnecessary external access, use strong passwords and enable multifactor authentication where available.

