Plex urged its users to update Plex Media Server and the Plex Desktop app immediately after releasing updates that address several security vulnerabilities. The company has not yet disclosed details about the vulnerabilities or their severity, and they have not received CVE numbers, but it confirmed that the issues affect Plex Media Server version 1.43.2 and earlier.
Plex sent emails to users running affected versions, reflecting its desire to encourage rapid updates rather than relying solely on a public announcement.
Required versions and dates
The company released Plex Media Server 1.43.3 to address a number of security issues and said server owners should install this version as soon as possible. According to the published information, the version was released on May 19, 2026. Plex also launched version 1.115.0 of Plex Desktop on August 13, 2026, and recommends that app users upgrade to it.
The versions can be downloaded from the official downloads page or the server management page. Users running Plex Media Server on NAS devices may not yet find the updated version in their device's package manager, so Plex indicated that the package can be installed manually.
Why does this warning matter?
The absence of CVE numbers and technical details makes it difficult to determine the scope of the impact or exploitation methods, but it does not eliminate the priority of updating. Plex's recommendation is based on the possibility that attackers may study the changes introduced by the new versions and then try to develop an exploit for older versions before the official details are published.
The product's history indicates that Plex servers have been targets of significant security issues. In August 2025, the company warned of a high-severity vulnerability designated CVE-2025-34158, which was reportedly capable of allowing attackers to steal server-owner credentials. In March 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the remote code execution vulnerability CVE-2020-5741 to its catalog of vulnerabilities known to be exploited.
Plex had also notified users of a data breach in August 2022 and asked them to reset their passwords after attackers accessed a database containing email addresses, usernames, and encrypted credentials. The current warning does not establish the presence of active exploitation or a connection to these previous incidents; the technical details of the new vulnerabilities have not yet been published.
What should be reviewed?
The immediate step for server owners and clients is to check the version number and update Plex Media Server to 1.43.3 and Plex Desktop to 1.115.0. NAS environments need to confirm that the package is available through the system manager or follow the manual installation option mentioned by the company. The nature of the vulnerabilities, whether they can be exploited, and whether they require additional protective measures remain open questions until the CVE numbers and associated details are published.