Over 36,000 exposed Plex servers remain vulnerable to recent security flaws, leaving users at risk of potential attacks. The issue affects those running older versions of Plex Media Server, with a total of over 36,000 instances still unpatched and exposed online.
Plex issued a warning last week for its users to secure their media servers immediately against multiple security vulnerabilities that are currently lacking CVE IDs for easy tracking. However, the company has not provided additional details on these issues. Affected versions include Plex Media Server v1.43.2 and earlier. Those running these versions should take action as soon as possible by upgrading their Plex Media Server installations to version 1.43.3 (released in May) and their Plex Desktop clients to 1.115.0 (released in August). These updated versions can be downloaded from the server management page or the official downloads page.
The nonprofit security organization Shadowserver has been actively scanning for unpatched versions of Plex Media Server, reporting daily on instances that remain vulnerable. According to Shadowserver’s findings, over 36,000 Plex Media Server instances exposed online are still unpatched and vulnerable to potential attacks. The group emphasizes that the lack of CVE IDs for these vulnerabilities makes them invisible to the security community, limiting an effective response.
This is not the first time Plex has been at the center of a major cybersecurity issue. In August 2025, the company warned users about a high-severity vulnerability (CVE-2025-34158) that can be exploited to steal server owner credentials. A similar vulnerability (CVE-2020-5741), flagged by CISA as actively exploited two years earlier, allowed attackers to make the server execute malicious code. This remote code execution flaw was likely used in a massive data breach in August 2022, where threat actors stole credentials and compromised the LastPass corporate vault.
In light of these events, it is essential for Plex users to take immediate action to secure their servers. Upgrading to the latest version of Plex Media Server and Desktop clients will help prevent potential attacks. However, it’s worth noting that even with valid credentials, only 37% of an attacker’s actions are blocked once they gain access. This highlights the importance of staying on top of security updates and patches.
In conclusion, users running older versions of Plex Media Server should prioritize upgrading to the latest version as soon as possible. While details about these specific vulnerabilities remain scarce, it is crucial for server owners to take proactive steps to prevent potential attacks. As a general rule of thumb, staying up-to-date with the latest security patches and updates will significantly reduce the risk of falling victim to cyber threats.
Source: Bleeping Computer — 2026-09-09