Tendvane

← All articles

SecuritySeptember 10, 2026

Plex asked everyone to update. 36,000 servers have not.

Plex broke its own habit on 1 September and emailed users directly, asking them to update. We wrote about it at the time. Somebody has now counted how many people actually did.

Shadowserver, the non-profit that scans the internet and tells network owners what it can see from outside, began daily reporting on unpatched Plex Media Server installations on 4 September. Every day since, it has found more than 36,000 instances reachable from the internet and still running 1.43.2 or earlier. The fix is not new: Media Server 1.43.3 shipped on 19 May, and Plex Desktop 1.115.0 on 13 August. So these are machines that have had a patch sitting available for close to four months.

The flaws still have no CVE identifiers. Plex's position remains that CVEs have been requested and details will follow. Shadowserver's objection is practical: with no identifiers the problem stays largely invisible to the people whose job is tracking it, and nothing feeds through into the scanners and advisories that would otherwise nudge owners into updating. The secrecy is a one-sided bargain in any case, because a patch is a public before-and-after. Anyone can compare 1.43.2 with 1.43.3 and work out what changed, and that clock has been running since May.

Doing it takes a minute from the server's own settings page. If your Plex lives on a Synology, QNAP or Unraid box, install the package by hand instead of waiting for the store copy, which tends to lag by days. And if the honest reason you have not updated is that the server has never quite been yours to look after, the one set up years ago that nobody thinks about, then that is the thing worth fixing. Tendvane's app update check runs through winget, Microsoft's own package tool, and keeps most ordinary desktop software current; a media server tucked away on a NAS in a cupboard is one you still have to go and see to yourself.

Sources

Download Tendvane