Plex Issues Urgent Advisory to Patch Multiple Security Vulnerabilities
Users advised to update Plex Media Server and Desktop clients to mitigate potential remote code execution risks

Key Takeaways
- Plex has urged users to update Plex Media Server and Plex Desktop clients immediately.
- Multiple security vulnerabilities have been identified, potentially allowing remote code execution or privilege escalation.
- No confirmed active exploitation has been reported at the time of the advisory.
- Updating to the latest versions of Plex Media Server and Plex Desktop is the recommended mitigation.
- Users running outdated software remain exposed to potential exploitation.
Quick answers
- What happened?
- Plex has urged users to update their desktop clients and media server software immediately to patch multiple security vulnerabilities. The advisory notes that unpatched versions may be susceptible to remote code execution or privilege escalation, though no active exploitation has been confirmed at the time of release.
- Which products are affected?
- Plex Media Server, Plex Desktop
- What should defenders do?
- Update to the latest version of Plex Media Server and Plex Desktop as released by Plex. Enable automatic updates where available. Monitor Plex security advisories for further details.
Plex has issued an urgent advisory prompting users to update their desktop clients and media server software immediately. The company stated that multiple security vulnerabilities have been identified that could potentially allow remote code execution or privilege escalation on systems running outdated versions. The advisory affects both Plex Media Server and Plex Desktop clients. Plex has not disclosed detailed technical specifics in the initial report, but emphasized that updating to the latest released versions is the recommended mitigation. As of the advisory date, no confirmed active exploitation of these vulnerabilities has been reported in the wild. The company encourages all users to apply the available patches to reduce their attack surface.
Security Details
Plex has identified multiple security vulnerabilities affecting Plex Media Server and Plex Desktop clients. The advisory indicates these flaws could allow remote code execution or privilege escalation on unpatched systems. Specific CVE identifiers and technical details were not included in the initial report. Plex has released updates to address the issues.
Affected products
Plex Media Server, Plex Desktop
Mitigation
Update to the latest version of Plex Media Server and Plex Desktop as released by Plex. Enable automatic updates where available. Monitor Plex security advisories for further details.
Sources
BleepingComputer
Plex warns users to patch security vulnerabilities immediately
Sep 3, 2026 · 11:02
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



