Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking.
While the company didn’t provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier.
Those running affected versions are advised to secure their systems as soon as possible by upgrading Plex Media Server installations to version 1.43.3 (released on May 19) and their Plex Desktop clients to 1.115.0 (released on August 13), which can be downloaded from the server management page or the official downloads page.
“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,” Plex said.
“CVEs have been requested and we’ll reply to this thread with more details once they’re published. If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually.”
On Friday, nonprofit security organization Shadowserver warned that over 36,000 Plex Media Server instances exposed online are still unpatched and vulnerable to potential attacks.

“Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex for v1.43.2 & earlier. Over 36K instances found still unpatched,” Shadowserver said.
“No CVEs have been issued meaning the vulnerabilities are invisible to the security community limiting an effective response.”
Although Plex hasn’t shared any details about these flaws so far, users should follow the company’s warning and secure their servers before attackers reverse-engineer the patches and develop an exploit, since this is one of a very limited number of instances where it has also emailed customers about patching their systems as soon as possible.
In August 2025, Plex warned users to patch a high-severity vulnerability now tracked as CVE-2025-34158 that can be exploited to steal the server owner’s credentials.
CISA also flagged a Plex Media Server remote code execution flaw (CVE-2020-5741) as actively exploited two years earlier, which can allow attackers to make the server execute malicious code.
While the cybersecurity agency has yet to share more information on the attacks exploiting CVE-2020-5741, it was likely used to hack the computer of a LastPass senior DevOps engineer, leading to a massive August 2022 data breach after threat actors stole credentials and compromised the LastPass corporate vault.
That same month, Plex notified users of a data breach, warning them to reset passwords after the attackers accessed a database containing emails, usernames, and encrypted credentials.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

