Plex Urges Users to Patch Their Servers Against Security Flaws
Do you use Plex Media Server at home or at work? You’ll need to install the latest security update! Plex has sent an email to its users urging them to move to a patched version, without providing any details about the flaws that were discovered. Here’s what we know.
On September 1, 2026, Plex published a message on its official forum to announce the availability of new versions. The headline refers to an important security update for anyone running Plex Media Server version 1.43.2 or earlier.
"We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to fix a number of security issues. We recommend that all server owners and Desktop users update to the latest version as soon as possible.", Plex wrote on its forum.
As a reminder, Plex Media Server is one of the most widely deployed media servers in home environments. It is often installed on a NAS, or directly on a PC, with or without Docker. It is also frequently exposed to the web in order to provide remote access to media, making it an attractive target.
Fixes Released, but No Technical Details
What stands out to me in Plex’s official message is the lack of detail. No CVE reference has yet been linked to the patched flaws. No severity score has been provided. No details have been given about what the newly discovered vulnerabilities could actually do. We know almost nothing. "CVE IDs have been requested and we’ll reply in this thread with more details once they are published.", Plex says.
In other words, Plex is telling us it’s urgent and that we should patch blindly. Are these critical flaws? Maybe. But the patched release, 1.43.3, is not new. It was released on May 19, 2026, and Plex Desktop 1.115.0 on August 13, 2026. So the fixes for Plex Media Server had already been available for several months before the vendor decided to alert users directly.
Plex may have good reasons to double down at the start of September. That is even more true given that Plex went as far as sending an email to its users asking them to update. It is not out of the question that one of these vulnerabilities is already being exploited, although that is only speculation.
This was already the channel used in August 2025, when I reported on a flaw disclosed through Plex’s Bug Bounty program and fixed in version 1.42.1.10060. The scenario is almost identical: an email, an instruction to update, and silence about the details.
How to Update Your Server
On your Plex server, check whether you are already running version 1.43.3 or later. The latest release is 1.43.4.X. If not, the installer is available on the official download page.
For NAS devices, the update may not yet be offered in the system’s app store, depending on your device brand. In that case, you can perform a manual package installation. Plex’s documentation also includes information about this process for QNAP, Synology, Terramaster, Western Digital, and Netgear NAS devices.


