Plex has warned that more than 36,000 internet-exposed Plex Media Server instances remain unpatched against multiple security flaws affecting Plex Media Server v1.43.2 and earlier. Users are urged to upgrade to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 before attackers reverse-engineer the fixes and exploit the vulnerabilities. #Plex #Shadowserver #CVE-2025-34158 #CVE-2020-5741
Keypoints
- Over 36,000 Plex Media Server instances are still exposed and unpatched online.
- The affected versions include Plex Media Server v1.43.2 and earlier.
- Plex advises updating to Media Server 1.43.3 and Desktop 1.115.0 immediately.
- Shadowserver reported daily scans showing more than 36K vulnerable instances.
- Past Plex flaws include CVE-2025-34158 and the actively exploited CVE-2020-5741.