Plex Servers Exposed: 36,000 Vulnerable to Security Flaws

www.news4hackers.com-plex-servers-exposed-36-000-vulnerable-to-security-flaws-plex-servers-exposed-36-000-vulnerable-to-security-flaws

Over 36,000 Plex Media Server instances accessible via the internet remain unpatched, exposing them to potential exploitation through multiple security flaws.

Unpatched Instances and Vulnerabilities

Over 36,000 Plex Media Server instances accessible via the internet remain unpatched, exposing them to potential exploitation through multiple security flaws. A recent alert from the Plex development team emphasized the urgency of addressing these vulnerabilities, which currently lack assigned Common Vulnerabilities and Exposures (CVE) identifiers. The affected versions include Plex Media Server v1.43.2 and earlier, with the company advising immediate mitigation steps.

Plex’s Response

Plex released updates to its software on May 19 and August 13, respectively, to resolve security concerns. Users are urged to upgrade their Plex Media Server installations to version 1.43.3 and Plex Desktop clients to 1.115.0. The company noted that while CVE numbers are being requested, details will be shared once published. For users operating Plex on network-attached storage devices, manual installation of the updated packages may be necessary as they might not yet appear in device-specific package managers.

Shadowserver’s Report

A cybersecurity nonprofit, Shadowserver, reported that more than 36,000 internet-facing Plex Media Server instances remain unpatched as of September 4, 2026. The organization highlighted that the absence of CVE identifiers complicates tracking and response efforts.

Historical Context of Security Issues

The vulnerabilities, though not yet publicly detailed, could be exploited by threat actors if reverse-engineered. Plex has previously communicated directly with users to prioritize patching, underscoring the severity of the situation. Historical context reveals recurring security challenges with Plex.

CVE-2025-34158 and CVE-2020-5741

In August 2025, a critical flaw tracked as CVE-2025-34158 was addressed, allowing attackers to steal server credentials. Earlier, in 2020, a remote code execution vulnerability (CVE-2020-5741) was flagged by the Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited.

Data Breaches

This flaw was linked to a 2022 data breach at LastPass, where attackers compromised a senior DevOps engineer’s device, leading to the exposure of corporate vault data. Plex also disclosed a data breach in the same month, prompting users to reset passwords after attackers accessed a database containing emails, usernames, and encrypted credentials.

Security Research and Recommendations

Security research indicates that 37% of malicious activities are blocked by existing defenses, though this leaves a significant gap in protection. The Blue Report 2026, analyzing 338 million simulations across enterprise environments, highlights the effectiveness of defensive measures against specific attack techniques.

Proactive Measures

Enterprises are advised to prioritize proactive patch management and monitor for indicators of compromise associated with unpatched systems. Technical teams are encouraged to verify their Plex server configurations, apply available updates, and implement network segmentation to limit potential attack surfaces.

Collaboration and Threat Intelligence

The lack of CVE identifiers for the current vulnerabilities necessitates close collaboration with vendors and threat intelligence sources to stay ahead of emerging threats.


Blog Image

About Author

en_USEnglish