Security2 distinct publishers2 min readPublished
Plex Media Server 1.43.3 and Desktop 1.115.0 fix flaws that still carry no CVE IDs and no description, which leaves anyone running the server on a NAS waiting on a package manager while the patched builds are already public.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Plex has published a version number and an instruction, not a vector [3]. The missing detail is the one triage depends on: whether anything fixed in 1.43.3 is reachable without an account on the server.
Last August's bug is the useful comparison. CVE-2025-34158, rated CVSS 8.5, had the `/myplex/account` endpoint hand the server owner's account details, including the administrative access token, to any authenticated non-owner or lower-privileged user [11]. A follow-up `/api/resources` call then enumerated the other servers that owner could reach, turning the pair into infrastructure discovery [12]. That chain needed an account, and plenty of home servers issue those to friends. With no equivalent detail on the current set, every owner has to patch as if the worst case applies.
The diff is the other half. BleepingComputer dates Plex Media Server 1.43.3 to May 19 and Plex Desktop 1.115.0 to August 13, and Plex withheld details on Tuesday [8][10]. Both patched builds were therefore downloadable before Plex said what they fixed [9]. Anyone comparing 1.43.2 with 1.43.3 starts from a fixed version pair and a narrow set of changed functions; BleepingComputer's own advice is to patch before attackers reverse-engineer the fixes and build an exploit [20]. The silence delays defenders more than it delays that work.
Censys counts more than 360,000 devices exposing the Plex Media Server web interface, and not all of them are vulnerable [7]. Read that as a measure of reachability, not of the bug. It is also a population with no central patch channel and no admin watching a forum thread.
The reason this matters past home libraries is documented, not theoretical. CISA flagged CVE-2020-5741, a Plex Media Server remote code execution flaw scored CVSS 7.2, as actively exploited in March 2023 [13][14]. That flaw was the way into a LastPass engineer's home computer, where attackers implanted keylogger malware [15]; they used the captured credentials to reach the LastPass corporate vault and steal database backups, producing the August 2022 breach [16]. Plex's other history is more mundane: a February 2021 fix stopped servers reflecting UDP packets to amplify denial-of-service traffic, restricting responses to the LAN from v1.21.3.4014 [17], and in August 2022 Plex told users to reset passwords after attackers reached a database of emails, usernames, and encrypted credentials [18].
Neither publisher reports exploitation of the flaws fixed this week, and no severity scores, affected components, or CVE numbers have been published [19]. The only public artifact is the patch, and on a NAS it arrives when the package maintainer gets to it [6].
Ranked by verification strength, evidence, and original report placement.
Plex said in an announcement this week: "We recommend all server owners and Desktop users update to the latest version as soon as possible."
The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0.
Plex did not elaborate on what the security issues are, but said CVE identifiers have been requested for them and that it will post details once published.
The security issues are known to affect Plex Media Server v1.43.2 and earlier, and have not yet been assigned CVE IDs.
Plex emailed users running affected versions asking them to update as soon as possible; BleepingComputer says this is one of the few instances where Plex has also emailed customers about upgrading their systems for a specific vulnerability.
Plex said that if Plex Media Server is running on a NAS device, the updated version may not be available in the device's package manager yet, but the package can be installed manually.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Mitsubishi's CNC advisory now lists 18 models exposed on TCP port 6831 distinct publisher
security
A low-privilege login reaches code execution on Rockwell's FactoryTalk Historian ME1 distinct publisher
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
security
Self-hosted ServiceNow operators inherit three unauthenticated CVSS 10.0 flaws to patch themselves2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Advisory verbatim, vulnerability unverifiable
Everything solid here is procedural: two build numbers, an affected-version floor, a NAS caveat. Both publishers quote the same Plex forum post, so the security substance rests entirely on the vendor's word and cannot be checked — no CVE, no component, no score. The well-documented parts of the story, the 2025 token leak and the 2020 RCE behind LastPass, are history rather than evidence about this patch.
Patches shipped, uptake unknown
The fixed builds have been downloadable for months — May 19 for the server, August 13 for the desktop client — and Plex went as far as emailing affected users, which tells you it does not believe they have installed them. Against that, the only population figure anyone offers is Censys's 360,000-plus exposed web interfaces, which counts reachable servers, not patched ones. Nobody reports how many have moved.
Urgency language ahead of stated facts
"Immediately" is doing work that the disclosed facts do not support. No exploitation is reported, no severity is published, and the server patch has sat in public since May — yet the framing is emergency. BleepingComputer is at least candid about why it presses: the risk is that someone diffs a patch that has been available for three months, which is an argument for speed and simultaneously an admission that the window opened long ago.
Vendor controls the silence
Plex is the only party who knows what was fixed and has chosen to say nothing until CVEs land — a posture that limits reverse-engineering but also spares it a described bug and shifts the NAS installation burden onto owners. The publishers' interest runs the other way, toward urgency; BleepingComputer's page carries a vendor security-report promotion beside the advice, which is worth noting without reading much into it.
Confident on the instruction, not the threat
Two independent outlets, one day apart, agree on every checkable particular — builds, affected range, NAS guidance, the pending CVEs — with no contradiction between them. That makes the remediation advice reliable. What no amount of agreement fixes is that both are relaying a single undocumented vendor statement, so any judgement about how badly you need to patch stays provisional.