Plex Security Warning: 36,000 Servers Found Unpatched

Plex administrators are being urged to update their servers after thousands of internet-exposed systems were found running vulnerable software.

Plex administrators are being urged to update their servers after thousands of internet-exposed systems were found running vulnerable software. Image: Generated via Google’s Nano Banana

More than 36,000 Plex Media Servers were found unpatched after a security warning. Here’s what administrators should know and how to update.

Written By
Matt Gonzales
Matt Gonzales
Sep 22, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Tens of thousands of internet-exposed Plex Media Servers remained unpatched days after Plex warned users to update vulnerable installations.

By Sept. 9, the Shadowserver Foundation had identified more than 36,000 internet-exposed Plex Media Server instances still running versions affected by recently disclosed security issues. The organization began scanning for vulnerable Plex servers after Plex issued its security warning on Sept. 1.

The 36,000 figure is an early-September snapshot, not a current count, and there is no evidence in the cited reporting that all of those servers were compromised or that the vulnerabilities are being actively exploited. Still, administrators running Plex Media Server 1.43.2 or earlier should update to version 1.43.3 or newer, preferably the latest version available for their platform.

More than 36,000 Plex servers remained vulnerable

Plex warned customers on Sept. 1 about multiple security issues affecting Plex Media Server 1.43.2 and earlier. The company urged administrators to update to version 1.43.3 or newer.

Shadowserver began scanning for potentially vulnerable Plex systems on Sept. 4. By the time the findings were reported Sept. 9, the nonprofit had identified more than 36,000 internet-exposed instances still running affected versions.

The situation highlights a recurring problem for security teams: releasing a fix does not eliminate a vulnerability if administrators do not install it.

That patching gap has surfaced elsewhere. Thousands of Zimbra installations remained exposed after attackers began targeting a critical flaw, with eSecurityPlanet detailing how more than 8,200 Zimbra servers were still unpatched as compromises mounted.

The Plex case is different. There is currently no comparable evidence in the cited reporting that the newly patched Plex vulnerabilities are being actively exploited. But tens of thousands of internet-facing installations were still running affected software more than a week after Plex's warning.

Advertisement

Plex has revealed little about the security flaws

Plex has disclosed relatively few technical details about the vulnerabilities.

The company's Sept. 1 advisory described multiple security issues and said CVE identifiers had been requested, but it did not provide detailed technical descriptions of the flaws. That gives defenders less information than a conventional vulnerability disclosure, where CVEs can make it easier to track affected versions, severity, exploitation and remediation.

Plex has continued updating Plex Media Server since the security warning. Version 1.43.4.10903 became generally available on Sept. 10, with Plex noting that availability through some app stores, including QNAP, could take additional time.

Administrators should therefore install the latest Plex Media Server release available for their platform rather than treating 1.43.3 as the final target.

The lack of detailed vulnerability information does not eliminate the need to update. Internet-facing applications can attract attention once security issues become public, even when technical details are limited.

Recent incidents involving other software show how quickly the situation can escalate. Attackers targeting a vulnerable WooCommerce plugin generated more than 100,000 blocked exploitation attempts, according to eSecurityPlanet's coverage of the WooCommerce attacks.

Why exposed servers deserve extra attention

The Plex numbers illustrate the difference between a vulnerability being patched and actually being removed from the internet.

A vendor can release an update, but affected installations remain exposed until administrators deploy it. Internet-facing servers deserve particular attention because attackers can use automated scanning to identify exposed services across large ranges of IP addresses.

Security teams have seen the same dynamic with enterprise software. More than 1,300 Microsoft SharePoint servers remained exposed to an actively exploited vulnerability even after fixes became available, as eSecurityPlanet previously examined.

For Plex users, however, the available evidence calls for some restraint. Shadowserver's count identified internet-exposed servers running affected software versions. It does not mean 36,000 Plex servers were successfully attacked, nor does the cited reporting establish active exploitation of the vulnerabilities.

Advertisement

What the number does show is that a sizable patching gap remained after Plex issued its warning.

What Plex administrators should do now

Anyone operating Plex Media Server should check the version currently installed rather than assuming an automatic update has already addressed the security issues.

Administrators should:

  • Update Plex Media Server: Install the latest version available for the server's platform. Plex's security advisory calls for version 1.43.3 or newer.
  • Verify the installed version: Confirm that the server has completed the update rather than relying solely on an update notification.
  • Check platform availability: Some third-party app stores can receive Plex releases later than Plex's direct distribution channels.
  • Review internet exposure: Determine whether the Plex server needs to be directly reachable from the public internet and reduce unnecessary exposure where practical.
  • Watch for additional disclosures: Look for CVE assignments, technical details or additional mitigation guidance from Plex and security authorities.
  • Review server activity: Administrators responsible for sensitive environments should examine available logs and telemetry for unexpected activity, particularly if a server remained internet-accessible while running an affected version.

The 36,000-server figure should not be interpreted as the number of vulnerable Plex systems online today. But the early-September snapshot shows how quickly a patching gap can leave thousands of internet-facing systems running affected software.

For Plex administrators, the most useful number to check now isn't 36,000. It's the version number running on their own server.

Related reading: For more on patching internet-facing systems, read about the SonicWall SMA1000 vulnerabilities being actively exploited.


Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.