Threat Intelligence

Plex Patches Multiple Undisclosed Security Flaws — Update Now

The Hacker News · 4 Sept 2026
Key Takeaway If your business uses Plex, update to Media Server 1.43.3 or Desktop 1.115.0 immediately rather than waiting for full details of the vulnerabilities to emerge.

Plex, the popular media streaming and server platform used by many small businesses and home users, has released critical updates addressing multiple security vulnerabilities. The fixes are included in Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0.

Plex has not published details about the specific nature of these flaws, but confirmed that CVE identifiers have been requested, indicating the issues are considered significant enough to be formally tracked in vulnerability databases. The company is strongly urging all server owners and desktop app users to update as soon as possible, a sign that the vulnerabilities could potentially be exploited if left unpatched.

Because Plex Media Server is often run continuously and can be accessible remotely, unpatched vulnerabilities in it can present a real risk, particularly for small businesses that use it to manage internal media libraries or share content with staff and clients. Even though full technical details haven't been disclosed publicly, history shows that attackers frequently move quickly to exploit known software flaws once patches reveal that a vulnerability exists.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.