More Than 36,000 Plex Media Servers Exposed to the Internet Remain Unpatched Against Recent Vulnerabilities

Views: 38 views

497/69 Thursday, September 10, 2026

Plex has issued an advisory urging administrators to update Plex Media Server and Plex Desktop after multiple security vulnerabilities were identified, though no official CVE identifiers have been assigned for tracking. The vulnerabilities affect Plex Media Server version 1.43.2 and earlier. Plex recommends that users upgrade Plex Media Server to version 1.43.3, released on May 19, and update Plex Desktop to version 1.115.0, released on August 13, to reduce the risk of exploitation.

The Shadowserver Foundation stated that, starting September 4, 2026, it began scanning and reporting Plex Media Server instances that remain unpatched based on Plex’s advisory. Shadowserver found more than 36,000 Plex Media Server instances exposed to the internet and still potentially vulnerable to attack. Shadowserver also noted that the absence of CVE identifiers makes it more difficult for the cybersecurity community to identify, track, and prioritize the risk, which may reduce the effectiveness of response and remediation efforts.

Plex has not disclosed technical details of the vulnerabilities. However, users should update their systems before threat actors can reverse-engineer the patches and develop exploits, especially given that Plex directly warned users to patch urgently, which is not a common occurrence. Plex has a history of vulnerabilities being exploited in attacks, such as CVE-2025-34158, which could be used to steal server owner credentials, and CVE-2020-5741, a remote code execution vulnerability that CISA previously listed as actively exploited. Administrators should check the versions of Plex Media Server in use, especially systems exposed to the internet, and apply updates as soon as possible.

Source: https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/