Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update Plex Media Server and Plex Desktop after releasing fixes for multiple security flaws, with CVE identifiers still pending. The alert follows past Plex issues, including CVE-2025-34158 and CVE-2020-5741, which were tied to account exposure and the LastPass breach. #Plex #PlexMediaServer #PlexDesktop #CVE-2025-34158 #CVE-2020-5741 #LastPass

Keypoints

  • Plex released updates for Plex Media Server 1.43.3 and Plex Desktop 1.115.0.
  • The company said CVE identifiers have been requested for the newly fixed flaws.
  • Users are advised to update as soon as possible, including manual installation on NAS devices if needed.
  • CVE-2025-34158 exposed server owners’ account details and administrative access tokens through API endpoints.
  • Past Plex vulnerabilities were linked to DoS abuse and the LastPass breach.

Read More: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html