• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Over 36,000 exposed Plex servers vulnerable to recent flaws

MrGuvernment

Fully [H]
2FA
Joined
Aug 3, 2004
Messages
24,286
If you run em, patch em, or something

Over 36,000 exposed Plex servers vulnerable to recent flaws​

https://www.bleepingcomputer.com/ne...s-unpatched-against-recently-disclosed-flaws/

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.

Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking.

While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier.

Those running affected versions are advised to secure their systems as soon as possible by upgrading Plex Media Server installations to version 1.43.3 (released on May 19) and their Plex Desktop clients to 1.115.0 (released on August 13), which can be downloaded from the server management page or the official downloads page.

"We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said.

"CVEs have been requested and we'll reply to this thread with more details once they're published. If you're running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually."

On Friday, nonprofit security organization Shadowserver warned that over 36,000 Plex Media Server instances exposed online are still unpatched and vulnerable to potential attacks.


Internet-exposed%20Plex%20Media%20servers.jpg
Internet-exposed Plex Media servers (Shadowserver)

"Since 2026-09-04 we are scanning/reporting daily unpatched versions of Plex Media Server in response to an advisory issued by Plex for v1.43.2 & earlier. Over 36K instances found still unpatched," Shadowserver said.

"No CVEs have been issued meaning the vulnerabilities are invisible to the security community limiting an effective response."

Although Plex hasn't shared any details about these flaws so far, users should follow the company's warning and secure their servers before attackers reverse-engineer the patches and develop an exploit, since this is one of a very limited number of instances where it has also emailed customers about patching their systems as soon as possible.

In August 2025, Plex warned users to patch a high-severity vulnerability now tracked as CVE-2025-34158 that can be exploited to steal the server owner's credentials.

CISA also flagged a Plex Media Server remote code execution flaw (CVE-2020-5741) as actively exploited two years earlier, which can allow attackers to make the server execute malicious code.

While the cybersecurity agency has yet to share more information on the attacks exploiting CVE-2020-5741, it was likely used to hack the computer of a LastPass senior DevOps engineer, leading to a massive August 2022 data breach after threat actors stole credentials and compromised the LastPass corporate vault.

That same month, Plex notified users of a data breach, warning them to reset passwords after the attackers accessed a database containing emails, usernames, and encrypted credentials.
 
The Emby subreddit is funny because they were blasting Plex for this number. Well yeah, more people use Plex, so of course it will be bigger. Emby and Jellyfin have had their own issues in the past. Throwing stones and such.
 
The Emby subreddit is funny because they were blasting Plex for this number. Well yeah, more people use Plex, so of course it will be bigger. Emby and Jellyfin have had their own issues in the past. Throwing stones and such.
And the usual, if you are hosting your own and have it open to the internet, with out making sure basics are there and secure and you are patching.. you are probably already compromised anyways
 
I only keep my Plex/Jellyfin VM hosting to internal & tunneled clients. Plus I always update it ASAP.
 
  • Like
Reactions: kac77
like this
Exploits? If you all want access to the "After Hours" just ask man. I'll send an invite.


I stay current with patches, plus, the Plex box only does Plex stuff and nothing else happens on it.
 
Exploits? If you all want access to the "After Hours" just ask man. I'll send an invite.


I stay current with patches, plus, the Plex box only does Plex stuff and nothing else happens on it.
Ya for most that may be the case, but if said box is compromised, what else can they get to from that box on your network, unless you got it isolated on its own VLAN.
 
It's isolated, I share libraries with friends, but I protect the rest of my boxes.

Trust nobody......
 
Back
Top