Plex told users on September 1, 2026 to update Media Server and Desktop immediately, warning that Media Server 1.43.3 and Desktop 1.115.0 patch a number of security issues affecting version 1.43.2 and earlier.
Plex has patched two products and wants every affected user updated now, according to Plex, before the bugs are even named publicly.
What to Know?
- Plex has requested CVE identifiers for the flaws but has not yet published technical details or a severity rating, per BleepingComputer.
- Plex emailed users running affected versions directly, asking them to update as soon as possible, a step it reserves, per BleepingComputer, for its more serious advisories.
- NAS-device package managers may lag behind the official release, so Plex is pointing affected users to manual installers by platform.
- The fixed versions are Plex Media Server 1.43.3, released May 19, and Plex Desktop 1.115.0, released August 13.
- Plex has patched multiple critical security flaws over the years, but this is one of the few instances where it has also emailed customers about upgrading to address a specific vulnerability.
How It Happened?
Plex posted the advisory to its official forums on September 1, giving no detail on how the flaws were found. We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible.
Plex confirmed CVEs have been requested and it will share more detail once they’re published, leaving the exact attack surface unconfirmed for now. The flaws are known to affect Plex Media Server v1.43.2 and earlier. A released patch can be reverse-engineered into a working exploit, a patch-gap window security researchers watch closely on any self-hosted server software.
🚨 Plex is sending emails to users urging them to update after releasing security fixes for multiple issues.
— Dark Web Informer (@DarkWebInformer) September 1, 2026
Plex says users should update to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 as soon as possible.
CVEs have been requested, with additional details expected once… pic.twitter.com/XkI3xJgOeh
Why the Silent Patch Matters?
Plex Media Server sits directly on a home network, often with port-forwarding enabled for remote streaming, which makes an unpatched instance a foothold rather than just a media-library bug. The company warned users in August 2025 about CVE-2025-34158, a high-severity flaw that let attackers steal the server owner’s credentials.
In March 2023, CISA flagged a Plex Media Server remote-code-execution flaw, CVE-2020-5741, as actively exploited, confirmation it had already been used in real attacks. That earlier RCE bug was likely linked to the 2022 hack of a LastPass DevOps engineer’s computer, where a third-party media software bug was the entry point attackers used to install keylogging malware and steal credentials.
A self-hosted app most people treat as entertainment software has, twice now, doubled as a route into far more sensitive systems, a risk pattern the Cybersecurity Attacks Statistics SQ Magazine maintains tracks across consumer-facing software, and one worth weighing alongside general cybersecurity threat data on how access flaws get chained into larger breaches.
SQ Magazine’s Takeaway
Plex withholding technical detail until CVEs publish is a defensible tradeoff, not a red flag. Naming the exact bug before most users have patched would help attackers more than it would help defenders. But the emailed alert, paired with a two-year pattern of RCE and credential-theft flaws in the same product, is a signal worth taking at face value. Treat this as a “patch today” notice, not a “patch eventually” one, especially if the server is reachable from outside the home network.
Updating helps reduce exposure to whatever these flaws turn out to be, though it doesn’t guarantee a server went untouched during the gap between the May and August releases and this week’s alert. NAS users whose package manager hasn’t caught up should install manually rather than wait, and anyone on an older, unpatched instance should treat locally stored credentials as worth a closer look.