Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking.
While the company didn’t provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier.
Those running affected versions are advised to secure their systems as soon as possible by upgrading Plex Media Server installations to version 1.43.3 (released on May 19) and their Plex Desktop clients to 1.115.0 (released on August 13), which can be downloaded from the server management page or the official downloads page.
“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,” Plex said.
“CVEs have been requested and we’ll reply to this thread with more details once they’re published. If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually.”
On Friday, nonprofit security organization Shadowserver warned that over 36,000 Plex Media Server instances exposed online are still unpatched and vulnerable to potential attacks.
“Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex for v1.43.2 & earlier. Over 36K instances found still unpatched,” Shadowserver said.
“No CVEs have been issued meaning the vulnerabilities are invisible to the security community limiting an effective response.”
Although Plex hasn’t shared any details about these flaws so far, users should follow the company’s warning and secure their servers before attackers reverse-engineer the patches and develop an exploit, since this is one of a very limited number of instances where it has also emailed customers about patching their systems as soon as possible.
In August 2025, Plex warned users to patch a high-severity vulnerability now tracked as CVE-2025-34158 that can be exploited to steal the server owner’s credentials.
CISA also flagged a Plex Media Server remote code execution flaw (CVE-2020-5741) as actively exploited two years earlier, which can allow attackers to make the server execute malicious code.
While the cybersecurity agency has yet to share more information on the attacks exploiting CVE-2020-5741, it was likely used to hack the computer of a LastPass senior DevOps engineer, leading to a massive August 2022 data breach after threat actors stole credentials and compromised the LastPass corporate vault.
That same month, Plex notified users of a data breach, warning them to reset passwords after the attackers accessed a database containing emails, usernames, and encrypted credentials.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Plex warns users to patch security vulnerabilities immediately
CISA orders urgent patching of actively exploited Zimbra flaw
Citrix urges admins to patch new NetScaler flaws as soon as possible
Zimbra urges customers to patch critical web client XSS flaw
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
What about their apps for Shield TV, Apple TV and and Roku that are used by people you share with?
“What about their apps for Shield TV, Apple TV and and Roku that are used by people you share with?” Those are not directly exposed like the server is and those a just clients, totally different thing than the server that does the sharing. Anyone that owns a server needs to be very careful. That LastPass hack that happened where they lost an encrypted backup of user accounts\passwords happened because an employee was targeted and they used his Plex server to get into his home network as the employee had left it unpacthed.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
N-able patches max severity N-central flaw amid ongoing attacks
See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.
Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions.
Overdue a password health-check? Audit your Active Directory for free
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


