Plex Urges Immediate Updates to Patch Multiple Undisclosed Security Flaws
Critical vulnerabilities affect Plex Media Server and Plex Desktop; CVE identifiers pending assignment

Key Takeaways
- Plex has released updates for Plex Media Server (1.43.3) and Plex Desktop (1.115.0) to patch multiple security flaws.
- The specific details of the vulnerabilities are not publicly disclosed.
- CVE identifiers have been requested but not yet assigned.
- Users are strongly advised to update to the latest versions to mitigate potential risks.
- No known active exploitation has been reported at the time of the advisory.
Quick answers
- What happened?
- Plex has released updates for Plex Media Server and Plex Desktop to address multiple security flaws. The company has not disclosed specific details of the vulnerabilities but confirms CVE identifiers have been requested. Users are strongly advised to update to the latest versions to mitigate potential risks.
- Which products are affected?
- Plex Media Server, Plex Desktop
- What should defenders do?
- Update Plex Media Server to version 1.43.3 or later and Plex Desktop to version 1.115.0 or later. Enable automatic updates if available. Monitor official Plex advisories for CVE assignments and additional details.
Plex has urged users to immediately update their Plex Media Server and Plex Desktop installations following the release of updates that patch multiple security flaws. The fixes are available in Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0.
According to the advisory, Plex did not elaborate on the specific nature of the security issues. The company stated that CVE identifiers have been requested for the vulnerabilities but have not yet been assigned. The advisory emphasizes that users running outdated versions of either product may be exposed to potential security risks.
Plex recommended that all server owners and Desktop users apply the updates as soon as possible. The company did not provide further details regarding the specific attack vectors or potential impact of the flaws, citing the pending CVE assignment as the reason for limited disclosure.
Security Details
Plex has released updates for Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0 to patch multiple security flaws. The specific nature of the vulnerabilities has not been disclosed, and CVE identifiers are pending assignment. Users running outdated versions may be exposed to potential security risks.
Affected products
Plex Media Server, Plex Desktop
Mitigation
Update Plex Media Server to version 1.43.3 or later and Plex Desktop to version 1.115.0 or later. Enable automatic updates if available. Monitor official Plex advisories for CVE assignments and additional details.
Sources
The Hacker News
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Sep 4, 2026 · 07:35
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


