Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Plex Urges Immediate Update for Security Patches

Plex Urges Immediate Update for Security Patches

Posted on September 4, 2026 By CWS

Plex has issued an urgent call for users to update their systems to the newest version after releasing patches for several security vulnerabilities. The updates are incorporated in Plex Media Server 1.43.3 and Plex Desktop 1.115.0, though the company has not disclosed the specific flaws addressed. Plex has requested CVE identifiers for these issues, underscoring the importance of the updates.

Plex’s Recommendations for Users

Plex has advised all server owners and desktop users to upgrade to the latest software without delay. However, those utilizing Plex Media Server on NAS devices might need to manually install the update if it’s not yet available through their package manager. This precaution is crucial for maintaining the security of personal and operational data.

Previous Security Flaws and Their Implications

In August 2025, Plex tackled a significant security issue, CVE-2025-34158, which had a CVSS score of 8.5. This flaw involved an authentication error at the “/myplex/account” endpoint, which could expose server owner details, including administrative tokens, to unauthorized users. Furthermore, an API call to “/api/resources” could enable attackers to discover additional servers, posing a potential risk to the complete Plex infrastructure.

Censys data indicates more than 360,000 devices expose Plex Media Server web interface, yet not all are necessarily vulnerable. Nevertheless, vulnerabilities in Plex have been exploited, such as in February 2021, when updates were released to prevent a denial-of-service (DoS) attack method that leveraged UDP reflection.

Impact of Past Security Breaches

Previous security breaches have highlighted the risks associated with vulnerabilities in Plex. Notably, a 2022 incident involving LastPass was traced back to a Plex Media Server vulnerability (CVE-2020-5741), which attackers exploited to install keylogger malware on an employee’s home computer. This breach underscores the critical need for regular updates and vigilance in maintaining security protocols.

The continuous discovery and patching of vulnerabilities are vital for the security of Plex users. By ensuring that all systems are up-to-date, users can protect themselves against unauthorized access and potential data breaches. As cybersecurity threats evolve, prompt updates and adherence to best practices in network security remain essential.

The Hacker News Tags:CVE, Cybersecurity, data protection, media streaming, NAS device, network protection, network security, Plex, Plex Desktop, Plex Media Server, security flaws, security update, software update, Vulnerabilities, vulnerability patch

Post navigation

Previous Post: Urgent Chrome Update Fixes Critical 0-Day Vulnerability
Next Post: DPRK-Linked Malicious macOS Installers Steal Credentials

Related Posts

Microsoft Defender Zero-Day Vulnerability Exposes System Access Microsoft Defender Zero-Day Vulnerability Exposes System Access The Hacker News
5 Threats That Reshaped Web Security This Year [2025] 5 Threats That Reshaped Web Security This Year [2025] The Hacker News
Citrix Urges Immediate Patching of Critical NetScaler Flaws Citrix Urges Immediate Patching of Critical NetScaler Flaws The Hacker News
Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts The Hacker News
Fortinet FortiSandbox Vulnerabilities Under Attack Fortinet FortiSandbox Vulnerabilities Under Attack The Hacker News
Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark