Plex is urging users to update after shipping fixes for multiple security flaws in its media server and desktop apps. The patched builds are Plex Media Server 1.43.3 and Plex Desktop 1.115.0, and the company says CVE identifiers have been requested for the issues without disclosing what they are.
“We recommend all server owners and Desktop users update to the latest version as soon as possible,” Plex said in an announcement this week. Owners running the server on a NAS should know the updated package may not yet be available in their vendor’s package manager and may need to be installed manually.
The advisory lands against a backdrop of steady interest in exposed Plex instances: Censys data shows more than 360,000 devices exposing the Plex Media Server web interface, though not all of them are vulnerable. The platform has been hit before, including an August 2025 authentication flaw (CVE-2025-34158, CVSS 8.5) that let lower-privileged users pull the server owner’s account details and access token from the /myplex/account endpoint, and a 2021 issue that allowed attackers to reflect UDP packets and amplify denial-of-service attacks.
Because Plex servers often sit on home networks with forwarded ports, owners should update promptly and reconsider whether remote access is needed at all. Restricting or disabling remote access shrinks the attack surface while the requested CVE identifiers and technical details remain pending.
