Vulnerability
Published 2026-09-01
Verified 2026-09-19

Plex: Media Server 1.43.3 and Desktop 1.115.0 security update; 36k+ still exposed

Plex posted an official security notice on its forum on 1 September 2026 recommending that all Plex Media Server owners and Plex Desktop users update as soon as possible. Plex Media Server 1.43.3 and Plex Desktop 1.115.0 address a number of security issues. Plex says CVEs have been requested and that it will add details to the thread once they are published; this desk does not invent CVE identifiers or a CVSS. NAS package managers may lag; Plex says the updated package can be installed manually from its Downloads page. BleepingComputer (3 September 2026) reports Plex also emailed owners of affected versions urging immediate upgrade — unusual for the vendor — while still withholding vulnerability details. NEW 9 Sep: BleepingComputer citing Shadowserver says daily scans since 4 September 2026 still find over 36,000 internet-exposed Plex Media Server instances on vulnerable 1.43.2-and-earlier builds, with missing CVEs limiting automated detection. Automatic-update users should confirm they are on 1.43.3 or newer.

Product
Plex Media Server; Plex Desktop
Versions
Plex Media Server 1.43.2 and earlier
Exploited in Australia?
unknown
Patch to
Plex Media Server 1.43.3 or later; Plex Desktop 1.115.0

Primary: Plex Forum security notice (1 Sep 2026) · Vendor: Plex (vendor) · BleepingComputer (9 Sep 2026; Shadowserver 36k+ exposed)

tech cloud