SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Plex Releases Security Fixes for Media Server and Desktop Clients - Users Urged to Update Immediately

Plex Releases Security Fixes for Media Server and Desktop Clients - Users Urged to Update Immediately

Plex has released security updates for Plex Media Server and Plex Desktop and is urging users to upgrade immediately. Plex Media Server v1.43.2 and earlier should be moved to version 1.43.3; Plex Desktop should be updated to 1.115.0. CVE identifiers have been requested, and full technical details are not public yet. This article covers the fixed versions, how to update across Windows, macOS, Linux, NAS, Docker, and other platforms, and what administrators should do now.

Sep 15, 2026By Bapanapalli Prem Sai Siddhik

Summary

Plex has issued a security update for Plex Media Server and Plex Desktop and recommends that all server owners and Desktop users apply it as soon as possible. CVE identifiers have been requested; technical details will follow when they are published.

Why This Matters

Plex has not published severity scores or root-cause detail, but it has framed the release as a security update and asked for immediate action. Media servers are often reachable beyond the local network. Delaying the update could increase the risk of exploitation, particularly once technical details or proof-of-concept research becomes available especially where remote access is enabled or the server runs on a NAS that lags behind package-manager updates.

Affected and Fixed Versions

Affected:

  • Plex Media Server v1.43.2 and earlier

Fixed in:

  • Plex Media Server 1.43.3
  • Plex Desktop 1.115.0

Packages are available from the Plex downloads page.

How to Update

Platform-specific steps are listed in the official Plex security announcement. In summary:

  • Windows and macOS: Confirm automatic updates reached the fixed server build, or install manually from the downloads page.
  • Linux (Ubuntu): Install the current .deb with sudo dpkg -i using the file downloaded.
  • Linux (Fedora/CentOS): Install the current .rpm with sudo dnf install using the file downloaded.
  • Docker: Use the guidance in the official pms-docker repository.
  • NVIDIA SHIELD: Install pending updates from the Google Play store.
  • NAS systems: The fixed package may not appear in the vendor store yet. Download the correct build from Plex, open the NAS web interface, use the app store's manual install path (App Store / App Center / Applications), and complete the wizard.

Device-specific guides linked by Plex:

If installation fails, check the Plex Media Server NAS forums for device-specific guidance.

Recommended Actions

  • Move every server and Desktop client to the fixed releases listed above.
  • On NAS, use manual install when the store is still on an older build.
  • Confirm the running version in server settings after the upgrade.
  • Watch the Plex announcement thread for CVE IDs when they are published.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical third-party application updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026

Open Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

CVE Research

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026