Plex warns users to patch security vulnerabilities immediately
Key Points:
- Plex has urged users to immediately update their desktop clients and media servers to patch multiple security vulnerabilities affecting Plex Media Server v1.43.2 and earlier, as well as Plex Desktop.
- The company released Plex Media Server 1.43.3 on May 19 and Plex Desktop 1.115.0 on August 13 to address these issues, recommending all users upgrade promptly to secure their systems.
- Plex has not yet provided detailed information or assigned CVE IDs for the vulnerabilities but has requested CVEs and plans to share more details once available.
- This update notification is notable as Plex rarely emails customers about specific vulnerabilities; previous critical flaws included a high-severity credential theft bug in 2025 and a remote code execution flaw flagged by CISA in 2023.
- Past exploitation of Plex vulnerabilities has led to significant security incidents, such as the 2022 LastPass breach where attackers used a media software RCE bug to install malware and steal credentials.