Plex is urging users to update its desktop client and media server software after releasing fixes for multiple security issues, according to BleepingComputer. The company’s guidance applies to Plex Media Server owners and Plex Desktop users, with the affected server versions identified as Plex Media Server v1.43.2 and earlier. BleepingComputer reports that Plex told users it had released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address “a number of security issues,” and recommended updating to the latest versions as soon as possible. The report says Plex also emailed users running affected versions with the same upgrade guidance. The company has not yet published technical details for the flaws. According to BleepingComputer, Plex said CVE identifiers have been requested and that it would provide more information once those identifiers are published. That leaves administrators without the usual vulnerability records used to track severity, exploitability and exposure across asset inventories. The update path depends on where Plex is running. BleepingComputer says Plex Media Server 1.43.3 was released on May 19, while Plex Desktop 1.115.0 was released on August 13. Plex told users they can get updates through the official downloads page or the server management page; users running Plex Media Server on a network-attached storage device may need to install the package manually if their NAS package manager does not yet offer it. The lack of public vulnerability detail cuts both ways. It limits immediate defensive triage, but it also means attackers may attempt to infer the bugs by comparing patched and unpatched versions. BleepingComputer’s recommendation is straightforward: update before attackers have time to reverse-engineer the patches into working exploits. The report also notes that Plex has patched serious flaws before. In August 2025, Plex warned users about a high-severity vulnerability tracked as CVE-2025-34158 that could allow attackers to steal a server owner’s credentials, according to BleepingComputer. In March 2023, the U.S. Cybersecurity and Infrastructure Security Agency flagged a Plex Media Server remote code execution flaw, CVE-2020-5741, as actively exploited. For operators, the practical takeaway is narrower than a full incident report but urgent enough to act on: identify Plex Media Server and Plex Desktop installations, confirm their versions, and update any systems below the fixed releases. Until Plex publishes CVEs and technical advisories, the known facts are the affected product families, the fixed versions and the company’s request to patch quickly. Who benefits: Users and administrators who update promptly reduce exposure before more technical details become public. NAS users who manually install the fixed package may close the gap before their device vendor’s package manager catches up. Who's exposed: Plex Media Server installations on v1.43.2 or earlier are the clearly identified affected systems in the report. Plex Desktop users who have not moved to version 1.115.0 are also within Plex’s update guidance.