started · updated
Plex urges immediate updates to patch undisclosed security flaws
Plex is urging users to immediately update their software to patch multiple undisclosed security vulnerabilities. The fixes are included in Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0.
While the specific nature and severity of these flaws have not yet been detailed, Plex has requested CVE identifiers and promised more information once they are assigned. The company has reportedly sent alert emails to users running affected versions.
For users running Plex Media Server on NAS devices, the company warns that the updated version might not yet be available through standard package managers, recommending a manual installation instead. Data from Censys indicates that over 360,000 devices are currently exposing a Plex Media Server web interface to the internet.