Plex issues urgent patch warning, 300,000 media servers can be found online
Thousands of Plex owners haven’t patched their servers to address a previous severe vulnerability from last year.

Image by Shutterstock
- Plex urges users to update Plex Media Server 1.43.2 and earlier, plus Plex Desktop.
- The updates fix several security issues, but Plex has not shared technical details yet.
- ShadowServer found nearly 300,000 exposed Plex instances worldwide, with the largest number in the US.
- More than 2,400 Plex instances remain vulnerable to a severe 2025 flaw that can enable unauthorized access.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Plex, a popular self-hosted media streaming platform, has issued an urgent warning to update Plex Media Servers and the Desktop client app to the latest versions, which have been available for a while now.
Plex issued a security notice this week, warning users that it is important to update Plex Media Server v1.43.2 and earlier to the latest version. The warning was also emailed to users directly.
Plex Media Server (PMS) is a free self-hosted service that streams and organizes a personal collection of movies, TV shows, music, and photos to any device that can reach it. Servers exposed directly to the open internet are likely lucrative targets for attackers.
“We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,” the Plex notice reads.
The alert timing is notable – the actual patches have been available for weeks or months now: PMS version 1.43.3 was first released in the Beta channel on June 22nd, 2026, and made available to everyone in July. The latest build was released on August 12th.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The changelogs listed several bugs that the latest releases addressed, including accepting crafted API requests with invalid URIs (Uniform Resource Identifiers), a potential vulnerability in the CompanionProxy component, which handles network traffic, and the ability to modify TranscoderH264Options and TranscoderH264OptionsOverride preferences over the network.
Plex says CVE (Common Vulnerabilities and Exposures) IDs have been requested, hinting that more details will be available once they’re published.
The latest version of the Plex Desktop client for Windows was released on August 13th, 2026.
Plex advisory contains guides on updating Plex servers across various platforms, including Windows, macOS, Linux, Android (Nvidia Shield), Docker, and NAS systems. If the updated version is not available in the package manager for a specific NAS device, Plex recommends downloading and updating it manually.
Public scans by ShadowServer Foundation reveal nearly 300,000 exposed Plex instances worldwide, most of which, 134,800, are in the US, followed by 21,300 in the UK, 19,500 in Canada, 13,600 in both France and Canada, 12,700 in Australia, 10,700 in the Netherlands, and thousands in other countries.
Over 2,400 instances are still vulnerable to CVE-2025-34158, a severe vulnerability from 2025, that allows privilege escalation, persistent unauthorized access, and difficulty in properly revoking compromised credentials.
China-Nexus cyber espionage actors have previously been observed leveraging a hacked Plex instance as a command-and-control server to target and control routers.
However, Plex currently deliberately withholds technical details about the types of vulnerabilities affecting the unpatched later versions of its software.