- What: Plex issues urgent security updates
- Impact: Users of older Plex versions at risk
Patch/Configuration Management Plex urges immediate updates for media server and desktop clients due to security vulnerabilities September 4, 2026 Share By SC Staff As reported by Bleeping Computer, Plex has issued an urgent call for users to update their desktop clients and media servers to address multiple security vulnerabilities affecting versions prior to Plex Media Server v1.43.3 and Plex Desktop 1.115.0. While specific CVE identifiers have not yet been assigned, Plex has directly emailed users, emphasizing the critical need to update to the latest versions to mitigate these security risks. The company stated that CVEs have been requested and further details will be provided upon publication. Users running Plex Media Server on NAS devices are advised to manually install the updated package if it's not yet available through their device's package manager. This advisory follows a history of security concerns, including a high-severity vulnerability (CVE-2025-34158) in August 2025 that allowed for credential theft, and a previously exploited remote code execution flaw (CVE-2020-5741) in March 2023. The latter was linked to the LastPass breach, where a third-party media software vulnerability was used to install malware. Plex itself experienced a data breach in August 2022, leading to a recommendation for users to reset passwords. Source: Bleeping Computer SC Staff Related Vulnerability Management SonicWall advises customers to patch two new SMA1000 zero-days Steve Zurier September 2, 2026 Attackers are chaining two SonicWall SMA1000 zero-days to gain remote code execution. Application security JFrog Artifactory flaw exploited days after patch release Steve Zurier September 1, 2026 Attackers exploited a JFrog Artifactory flaw days after its patch, threatening software supply chains. Vulnerability Management PaperCut issues emergency patches for actively exploited critical vulnerability Laura French August 28, 2026 Two flaws in the print management software could enable unauthenticated RCE. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds