- The Mess: Plex has quietly patched multiple security issues in Plex Media Server and Plex Desktop and is telling users to update immediately. The unusual part: the company requested CVE identifiers, but has not yet published the vulnerability details.
Plex Media Server 1.43.2 and earlier are affected.
Plex Desktop versions before 1.115.0 are also below the recommended security baseline.
The company’s warning is unusually blunt for a product that normally ships updates with detailed release notes.
Plex says it released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address “a number of security issues” and recommends that all server owners and desktop users update as soon as possible. Plex also confirmed that CVEs have been requested and that more information will follow once they are published.
That leaves administrators with an uncomfortable situation.
There is a patch.
There is a security warning.
There are vulnerabilities.
There are currently no public CVE identifiers explaining exactly what attackers can do.
- The Damage: A vulnerable Plex server can expose a machine that is often connected to personal files, NAS storage and other devices on a home or small-business network.
Plex Media Server is not just a video player.
It indexes media libraries, communicates with network storage, handles remote connections and often runs continuously on NAS devices, home servers and small computers.
That makes the server itself an interesting target.
Plex has had serious security incidents before.
In 2023, CISA added an older Plex Media Server remote-code-execution vulnerability, CVE-2020-5741, to its Known Exploited Vulnerabilities catalog after exploitation was observed. A separate Plex vulnerability disclosed in 2025 could allow attackers to steal server-owner credentials.
The current vulnerabilities are not yet publicly mapped to CVEs, so it would be reckless to claim that they provide RCE or credential theft without evidence.
But Plex clearly considers them serious enough to email affected users directly and tell them to update immediately.
There is another wrinkle for NAS owners.
Plex notes that updated packages may not immediately appear in the package managers of NAS platforms. Users may therefore have to wait for their vendor’s package approval or install the appropriate Plex package manually.
That creates a potentially awkward patch gap.
The Plex server can be fixed.
The NAS vendor’s repository can still be behind.
Security does not care which package manager is responsible.
There are already clues about at least some security-related changes in the 1.43.3 release series.
Plex’s release history includes a fix for a potential CompanionProxy vulnerability and another change preventing network modification of certain transcoder preferences.
However, Plex has not confirmed that these individual fixes represent the complete set of vulnerabilities covered by its September security warning.
That distinction matters.
Until Plex publishes the requested CVEs and technical details, defenders should not invent an exploit chain from release notes.
They should simply close the vulnerable version window.
- The Fix: Upgrade Plex Media Server to 1.43.3 or later and Plex Desktop to 1.115.0 or later, then verify the actual server version rather than assuming that a newer Plex Web interface means the server itself is patched.
Administrators running Plex on NAS devices should check the installed server version directly.
Do not rely on the NAS vendor’s update notification alone.
If the package repository still offers an older build, check Plex’s supported installation method and update accordingly.
Organizations and technically inclined home users should also review whether Plex Remote Access is actually required.
An Internet-facing media server has a much larger attack surface than one accessible only from a trusted LAN or through a properly secured VPN.
And if the server was running an affected version while exposed to the Internet, administrators should keep logs and monitor for suspicious activity even after applying the update.
Patching closes the vulnerability.
It does not tell you whether somebody already walked through it.
Bugstoday Opinion
This is a particularly annoying kind of security advisory.
“We fixed several security problems. Update now. We’ll tell you what they were later.”
From Plex’s perspective, delaying technical details can make sense. Giving attackers a complete roadmap before the majority of installations are patched is not exactly helpful.
For defenders, however, it creates a blind spot.
No CVE.
No CVSS.
No exploit details.
No reliable way to determine the blast radius.
Just a vendor saying:
Patch. Now.
And honestly, that’s enough.
Plex has a history of vulnerabilities becoming interesting once attackers start looking closely. Waiting for the CVE number before updating a server that is already known to be below the vendor’s security baseline is backwards.
Patch first.
Reverse-engineer the mystery later.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
Plex — Important Security Update for Plex Media Server v1.43.2 and Earlier
Plex — Plex Media Server Release Notes
BleepingComputer — Plex Security Update Analysis
RunZero — Plex Media Server Vulnerability Exposure Analysis
CISA — Known Exploited Vulnerabilities Catalog




