Plex patches undisclosed security flaws; over 36,000 exposed servers remain unpatched
Plex released fixes for multiple undisclosed security vulnerabilities in Plex Media Server 1.43.3 and Plex Desktop 1.115.0, urging immediate updates. Censys data counted over 360,000 exposed Plex Media Server web interfaces, and BleepingComputer later…
Plex shipped fixes for multiple undisclosed security flaws in Plex Media Server 1.43.3 and Plex Desktop 1.115.0, urging all users to update immediately. CVE identifiers have been requested and technical details have not yet been published. Exposure and patch-adoption figures differ between the two reports and measure different things: Censys data (cited by The Hacker News on 2026-09-04) showed more than 360,000 devices exposing the Plex Media Server web interface, while BleepingComputer (2026-09-09) reported more than 36,000 internet-exposed Plex Media Server instances had not yet applied the available patches, leaving them open to attack until administrators update. The reports do not reconcile the two figures. Guidance includes updating servers, limiting direct internet exposure (BleepingComputer), and manually installing updated packages on NAS setups (The Hacker News). Historical context: the 2022 LastPass breach involved exploitation of past Plex flaw CVE-2020-5741 (CVSS 7.2) to implant a keylogger on an employee's home computer, and CVE-2025-34158 (CVSS 8.5), an authentication bug, was patched in August 2025.
- Fixes shipped in Plex Media Server 1.43.3 and Plex Desktop 1.115.0 for multiple undisclosed security flaws (The Hacker News, 2026-09-04)
- CVE identifiers requested; flaw details not yet published (The Hacker News)
- Censys data shows over 360,000 devices exposing the Plex Media Server web interface (The Hacker News, 2026-09-04)
- Over 36,000 internet-exposed Plex Media Server instances remain unpatched against the recently disclosed flaws (BleepingComputer, 2026-09-09)
- The 360,000 and 36,000 figures come from different sources and measure different things (total exposed web interfaces vs. unpatched exposed instances); the reports do not reconcile them
- Unpatched instances are vulnerable to attack until the available updates are applied (BleepingComputer)
- Past Plex flaw CVE-2020-5741 (CVSS 7.2) was used to implant a keylogger on a LastPass employee's home computer during the 2022 LastPass breach (The Hacker News)
- CVE-2025-34158 (CVSS 8.5), a Plex authentication bug, was patched in August 2025 (The Hacker News)
Coverage timelineoldest first · each row is one article
- · 12d agoPlex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
The Hacker News· 45
Plex patched multiple undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0, urging all users to update immediately.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5741 | Authenticated Deserialization RCE in Plex Media Server on Windows CVE-2020-5741 is a deserialization-of-untrusted-data flaw (CWE-502) in Plex Media Server on Windows: the server deserializes a serialized Python (pickle) object supplied over the network without adequate validation. A remote attacker who has already authenticated with high-privilege credentials to the server can submit a maliciously crafted serialized object, causing the server to execute arbitrary Python code upon deserialization. Successful exploitation yields code execution in the context of the Plex Media Server process on the Windows host, exposing that machine's data and credentials and, as demonstrated in the 2022 LastPass breach, potentially providing a foothold into connected environments. Windows installations running a release without the vendor's 2020 security fix are affected; Linux/NAS deployments are outside the described scope of this flaw. Exploitation is confirmed: it carries a 72.9% EPSS probability (99th percentile), has public PoC exploits (Tenable TRA-2020-32 and a PacketStorm write-up), was added to CISA's KEV catalog on 2023-03-10, and is publicly linked to the LastPass breach, where an unpatched Plex Media Server on an employee's PC was the entry point. Do: Update Plex Media Server on every Windows host to the latest release per vendor instructions (a fix shipped in 2020), prioritizing machines used by staff with privileged or remote access, and verify versions by inventory since unpatched instances remain common. Because exploitation requires authenticated high-privilege Plex credentials, review and rotate those credentials and check affected hosts for indicators of compromise such as unexpected processes or lateral movement, as demonstrated in the LastPass incident. | 7.2 | 73% | KEV PoC ×2 |
| large≈300,000+ exposed/vulnerable Plex Media Server instances, with the Windows subset affected by this flaw | |
| CVE-2025-34158 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). NVD description · AI analysis pending | 8.5 | <1% | — | — |