Over 36,000 Plex Media Servers Remain Unpatched Against Security Vulnerabilities

More than 36,000 Plex Media Server instances remain exposed to the internet while running versions vulnerable to security flaws that have been patched for months. Despite the availability of a fix since May 19, 2026, many server administrators have failed to update, leaving their hardware and media libraries open to potential exploitation.

The Shadowserver Foundation began daily scanning for these unpatched instances on September 4, 2026, highlighting a significant security gap in the Plex ecosystem. The vulnerabilities specifically affect Plex Media Server version 1.43.2 and all earlier releases. To mitigate the risk, users are advised to upgrade to Plex Media Server version 1.43.3 and ensure the Plex Desktop application is updated to version 1.115.0 or later.

An abstract digital network map showing exposed server nodes.
data shows over 36,000 instances remain exposed to potential exploitation.

The Danger of “Invisible” Vulnerabilities

A primary concern for security researchers is the lack of public documentation for these specific flaws. While Plex has reportedly requested CVE identifiers for the issues, they have not been published as of September 9, 2026. This absence of formal identifiers often makes vulnerabilities “invisible” to enterprise security scanners and automated patch management tools that rely on the National Vulnerability Database (NVD) for threat detection.

For administrators using Network Attached Storage (NAS) devices, the delay is often compounded by third-party package managers that do not always provide the latest Plex updates immediately after they are released by the vendor.

Contextualizing Plex Security Risks

This is not the first time Plex vulnerabilities have caused industry-wide concern. In late 2022 and early 2023, a high-profile breach of LastPass was traced back to a senior engineer’s home media server, which was compromised via an unpatched Plex vulnerability. That incident demonstrated how a personal media server could serve as an entry point for lateral movement into sensitive corporate environments.

More recently, CVE-2025-34158 was identified as a high-severity flaw that allowed unauthorized access to server owner account details. While that specific issue was addressed in August 2025, the current wave of unpatched servers indicates a recurring struggle with update adoption within the Plex community.

Experts suggest that the current 36,000 exposed servers may be susceptible to “patch-diffing,” a technique where attackers compare the code of the patched version (1.43.3) against the vulnerable version (1.43.2) to reverse-engineer an exploit. Because the fix has been public since May, the window for such analysis has been open for nearly four months. The Hacker News reports that the server software remains a popular target due to its widespread use and the high level of access it often requires on local networks.

To secure an installation, administrators should verify their current version in the Plex Web UI under Settings > Server > General. If an update is not automatically appearing, manual installation of the latest binaries from the official Plex website is recommended to bypass potential delays in app store or repository synchronization.

More From Category

More Stories Today