Major Security Alert: Over 36,000 Unpatched Plex Media Servers Exposed Online
In a troubling revelation, nonprofit security organization Shadowserver has reported that more than 36,000 Plex Media Server installations remain vulnerable to recently disclosed security flaws. These installations are accessible over the internet and are running versions of Plex Media Server 1.43.2 or earlier. Despite an urgent alert issued by Plex to its users over a week ago, these systems have yet to be patched. The company had earlier released security updates in May and August of 2025 but has not provided further technical details regarding the vulnerabilities, nor have they assigned Common Vulnerabilities and Exposures (CVE) identifiers for better tracking.
On Tuesday, Plex took an unusual step by warning its server owners and desktop users to update their systems immediately. This public outreach included direct emails sent to customers, urging them to take swift action. Plex strongly recommends upgrading to Plex Media Server version 1.43.3, which was released on May 19, and the Plex Desktop client version 1.115.0, made available on August 13. Users running Plex on network-attached storage (NAS) devices may need to manually install the updates if the latest version is not yet available through their package managers.
The absence of CVE identifiers presents a significant blind spot for the cybersecurity community. This makes it exceedingly difficult for security experts to track and respond to vulnerabilities utilizing standard vulnerability management systems. Shadowserver initiated its daily scanning and reporting of unpatched Plex installations on September 4, 2026. It continues to discover tens of thousands of exposed systems online. Due to the lack of public technical details regarding these vulnerabilities, security teams find it hard to assess their risk effectively or prioritize patching efforts using conventional IT tools.
Plex has previously faced serious security incidents that highlight the urgent need for prompt updates. In August 2025, Plex addressed CVE-2025-34158, a high-severity vulnerability that could facilitate credential theft. Furthermore, a few years earlier, the Cybersecurity and Infrastructure Security Agency (CISA) flagged another significant vulnerability, CVE-2020-5741, which allowed for remote code execution in Plex Media Server. This vulnerability was reportedly part of the attack chain that compromised a senior DevOps engineer at LastPass, culminating in a massive data breach in August 2022 when attackers stole sensitive credentials and accessed the LastPass corporate vault.
The alarming number of exposed, unpatched servers, combined with Plex’s proactive communication to users, underscores the critical need for immediate action. Server administrators are advised to treat this warning with the utmost urgency. They should promptly update their Plex installations, even in the absence of detailed vulnerability information. The potential for exploitation of these unpatched servers is significantly heightened given Plex’s history and the quantity of vulnerable systems exposed online.
Administrators can download the latest versions directly from the Plex server management page or the official downloads site. After completing the update, it is highly recommended that users verify the successful installation of the latest software to ensure their systems are secure.
In conclusion, as cyber threats continue to escalate, the responsibility lies with server administrators to act swiftly. The lack of detailed technical information from Plex makes proactive updates even more critical. Cybersecurity experts urge all Plex users to remain vigilant, maintaining updated systems to safeguard their data and networks. The precarious situation of unpatched installations could potentially invite serious repercussions, making prompt remediation not just a best practice, but a necessity in today’s continually evolving digital landscape.
