Plex this week urged users to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. The flaws affect Plex Media Server version 1.43.2 and earlier, as well as the Plex Desktop client. While the company has not yet assigned CVE IDs or disclosed specific technical details, it has confirmed that security issues are present in these versions.
'We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible,' the company said in a forum post. 'CVEs have been requested and we'll reply to this thread with more details once they're published.'
Plex also emailed users on affected versions, a step it has taken only rarely in the past for specific vulnerabilities. The fixed versions—Media Server 1.43.3 (released May 19) and Desktop 1.115.0 (released August 13)—can be downloaded from the official Plex downloads page or the server management interface.
The company noted that users running Plex Media Server on a NAS device may need to install the update manually, as the updated version may not yet be available through the device's package manager.
Although no details have been shared about the vulnerabilities so far, security experts warn that users should act quickly before attackers reverse-engineer the patches and develop exploits. This is not the first time Plex has faced such issues: in August 2025, the company warned users to patch a high-severity vulnerability (CVE-2025-34158) that could allow threat actors to steal server owner credentials. In March 2023, CISA flagged an actively exploited remote code execution flaw (CVE-2020-5741) in Plex Media Server.
Plex recommends all server owners and desktop users upgrade as soon as possible to protect their systems from potential attacks.