Plex has urged users to immediately update Plex Media Server and Plex Desktop to address multiple undisclosed security vulnerabilities. The affected Media Server releases are version 1.43.2 and earlier; Plex issued Media Server 1.43.3 and Plex Desktop 1.115.0 as the remediated versions and has requested CVE assignments.
Plex has not disclosed technical details of the flaws, leaving defenders with limited information while increasing the risk that attackers could reverse-engineer the updates to identify vulnerable systems. Organizations running Plex on NAS devices should verify availability through their vendor package manager and manually install the updated server package where the vendor has not yet published it.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
A Metasploit auxiliary scanner module, auxiliary/scanner/http/plex_media_server_file_read, was proposed to retrieve arbitrary files readable by a Plex Media Server instance. Its example targets port 32402 and requests /etc/passwd from localhost.
Plex released Plex Desktop version 1.115.0 to address the newly disclosed security issues.
Plex released Plex Media Server version 1.43.3 to remediate multiple security vulnerabilities affecting version 1.43.2 and earlier.
Plex warned users about the high-severity credential-theft vulnerability CVE-2025-34158 affecting Plex Media Server.
CISA added the Plex Media Server remote-code-execution vulnerability CVE-2020-5741 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation.
Attackers reportedly exploited Plex Media Server CVE-2020-5741 to compromise a LastPass employee's home computer during the LastPass breach and installed keylogger malware.
Shadowserver internet scans identified more than 36,000 publicly reachable Plex Media Server instances that remained vulnerable, including about 16,000 in the United States and nearly 1,550 in Germany. No active exploitation had been reported at the time of the report.
Plex disclosed multiple undisclosed vulnerabilities in Plex Media Server 1.43.2 and earlier and urged Media Server and Plex Desktop users to update immediately. Plex requested CVE assignments, withheld technical details pending publication, and emailed affected users; NAS users may need to manually install the patched server package.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcexakep.ru
Open sourcescworld.com
Open sourcecryptika.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourceforums.plex.tv
Open sourceplex.tv
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.