Over 36,000 Exposed Plex Servers Remain Unpatched
Plex is once again urging owners of home media servers to act before any technical explanation appears. On September 1, the company demanded that users update Plex Media Server to version 1.43.3 or newer, and Plex Desktop to 1.115.0, since the new builds close several security issues. For now, Plex has disclosed neither the mechanism of the flaws nor their possible consequences.
A Problem of Scale, Not Theory
The situation has ceased to be theoretical because of the sheer scale of aging installations. Since September 4, Shadowserver has been scanning the internet, and by September 9 it had discovered more than 36,000 publicly accessible Plex Media Servers running version 1.43.2 or below. The organization stresses that its check rests on the software version, so the figure does not signify 36,000 confirmed breaches.
Plex’s original advisory, an important security update for Plex Media Server v1.43.2 and earlier, laid out the recommended versions but withheld further specifics.
No CVEs Yet, and That Hampers Defenders
The patched issues as yet bear no published CVE identifiers, no CVSS scores, and no descriptions of the attack vectors. Plex has stated that it requested CVEs and will add details once they are assigned. As Shadowserver explains in its vulnerable HTTP reporting service, the absence of identifiers poses a serious obstacle for defenders, since scanners and vulnerability-management systems cannot properly track such problems.
How to Update Across Platforms
For Windows and macOS, Plex advises checking automatic updates or installing the fresh build manually. On Linux, the company suggests downloading the current package, and for Docker it points to the official repository. NAS owners must be more vigilant: the required version may not yet have appeared in the manufacturer’s store, so Plex permits manual installation of the package.
A Familiar Pattern of Closed Communication
Such tight-lipped communication is already familiar for Plex. In August 2025, the company similarly warned a portion of server owners about an urgent update, again without a technical description of the flaw. The problem later received an identifier and a high severity rating. The present warning spans a wider range of older versions, yet no connection between the two episodes has been declared.
Caution around Plex has historical roots. In 2023, the media server’s name surfaced in the investigation into the attack on LastPass. Attackers likely exploited an old Plex flaw on an engineer’s home computer as part of the intrusion chain. For the current vulnerabilities, however, there is as yet no confirmation of exploitation, so the cases cannot be compared directly.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.