# @PlexTV staff: About the recent security update

**URL:** <https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438>\
**Category:** Plex Players\
**Tags:** player-linux\
**Created:** [September 2, 2026, 8:46pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438 "2026-09-02T20:46:38Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cphusion](https://avatars.discourse-cdn.com/v4/letter/c/58956e/32.png) [@Cphusion](https://forums.plex.tv/u/Cphusion)\
**Post date:** [September 2, 2026, 8:46pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/1 "2026-09-02T20:46:38Z")

</div>

> [@Important Security Update for Plex Media Server v1.43.2 and earlier](https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319):
>
> We recently released Plex Media Server 1.43.3 and Plex Desktop 1.115.0 to address a number of security issues. We recommend all server owners and Desktop users update to the latest version as soon as possible. CVEs have been requested and we’ll reply to this thread with more details once they’re published. If you’re running Plex Media Server on a NAS device, the updated version may not be available in their package manager yet but you can install the package manually. Here’s a quick guide on ho…

You mentioned here that all Plex clients have gotten an update.

[https://forums.plex.tv/t/plex-for-mac-windows-and-linux/446435/140](https://forums.plex.tv/t/plex-for-mac-windows-and-linux/446435/140)

Even the officially supported Snap got this update.

[https://snapcraft.io/plex-desktop](https://snapcraft.io/plex-desktop)

But the officially supported Flatpak hasn’t gotten an update in 9 months on version 1.112.0 and is using EOL run time.  
[https://flathub.org/en/apps/tv.plex.PlexDesktop](https://flathub.org/en/apps/tv.plex.PlexDesktop)

Can you please update the officially support Flatpak to that version as well and also update the runtime to a support one when.

There have been PR’s for it been no one has taken any action on this.

[https://github.com/flathub/tv.plex.PlexDesktop/pulls](https://github.com/flathub/tv.plex.PlexDesktop/pulls)

Also see this topic which was created a year ago where this was asked and no Plex employee responded but one who said he contacted engineering and he couldn’t do more.

[https://forums.plex.tv/t/plex-tv-plex-plexdesktop-version-1-110-0-flatpak-needs-updating](https://forums.plex.tv/t/plex-tv-plex-plexdesktop-version-1-110-0-flatpak-needs-updating)

---

<div class="post-metadata">

**Author:** ![JCHH](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jchh/32/84326_2.png) [@JCHH](https://forums.plex.tv/u/JCHH)\
**Post date:** [September 2, 2026, 8:59pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/3 "2026-09-02T20:59:19Z")

</div>

I’m pretty sure the security update was for the server not client apps.

---

<div class="post-metadata">

**Author:** ![dokuro](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dokuro/32/329926_2.png) [@dokuro](https://forums.plex.tv/u/dokuro)\
**Post date:** [September 2, 2026, 9:01pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/4 "2026-09-02T21:01:44Z")

</div>

They explicitly say to update server and desktop, it says so in the first line of the announcement!

---

<div class="post-metadata">

**Author:** ![dane22](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dane22/32/4389_2.png) [@dane22](https://forums.plex.tv/u/dane22)\
**Post date:** [September 2, 2026, 9:22pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/5 "2026-09-02T21:22:35Z")

</div>

I have been told, that Plex is working on this @Cphusion

---

<div class="post-metadata">

**Author:** ![JCHH](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/jchh/32/84326_2.png) [@JCHH](https://forums.plex.tv/u/JCHH)\
**Post date:** [September 2, 2026, 9:26pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/6 "2026-09-02T21:26:28Z")

</div>

Sorry, my mistake.

---

<div class="post-metadata">

**Author:** ![Cphusion](https://avatars.discourse-cdn.com/v4/letter/c/58956e/32.png) [@Cphusion](https://forums.plex.tv/u/Cphusion)\
**Post date:** [September 3, 2026, 3:23am UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/7 "2026-09-03T03:23:25Z")

</div>

That’s great to hear! Thanks! 🙂

---

<div class="post-metadata">

**Author:** ![Plex\_AU](https://avatars.discourse-cdn.com/v4/letter/p/9d8465/32.png) [@Plex\_AU](https://forums.plex.tv/u/Plex_AU)\
**Post date:** [September 3, 2026, 2:47pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/8 "2026-09-03T14:47:46Z")

</div>

I’m a little confused with versions. the post said to update to version 1.43.3 for server but I have 1.43.4. It also says update plex clients to version 1.115.0 but mine say 4.160.0. So I’m a bit confused as to how versions work on different platforms. I’m running Plex server in a Proxmox LXC and clients through a desktop browser.

---

<div class="post-metadata">

**Author:** ![Crongl](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Crongl](https://forums.plex.tv/u/Crongl)\
**Post date:** [September 3, 2026, 3:04pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/9 "2026-09-03T15:04:52Z")

</div>

Plex Desktop is a desktop client application… It isn’t the same thing as the web client you’re using in browser

Presumably, you’re enrolled in the beta program for the server, as 1.43.4 is listed as available there

---

<div class="post-metadata">

**Author:** ![Crongl](https://avatars.discourse-cdn.com/v4/letter/c/4af34b/32.png) [@Crongl](https://forums.plex.tv/u/Crongl)\
**Post date:** [September 3, 2026, 3:11pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/10 "2026-09-03T15:11:03Z")

</div>

Would be nice if they publicized that officially…

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [September 3, 2026, 4:09pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/11 "2026-09-03T16:09:40Z")

</div>

We’re working on it.

---

<div class="post-metadata">

**Author:** ![stuvey](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@stuvey](https://forums.plex.tv/u/stuvey)\
**Post date:** [September 3, 2026, 5:11pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/12 "2026-09-03T17:11:03Z")

</div>

Is the team working on getting the update into the [https://downloads.plex.tv/repo/deb](https://downloads.plex.tv/repo/deb)? I only see 1.42.2 there. Based on the tone of the email I got I went to update immediately rather than wait for my nightly upgrade and was surprised to see it wasn’t available. 36 hours later and it’s still not there.

(Yes, I’m aware I can download the .deb manually but that’s not sustainable if the repository isn’t kept up-to-date – I use automated tooling to keep all my gear updated – so I shut the server off in the meantime until I know where my security updates are really coming from.)

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [September 3, 2026, 5:31pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/13 "2026-09-03T17:31:58Z")

</div>

Please see: [https://support.plex.tv/articles/235974187-enable-repository-updating-for-supported-linux-server-distributions/](https://support.plex.tv/articles/235974187-enable-repository-updating-for-supported-linux-server-distributions/)

---

<div class="post-metadata">

**Author:** ![stuvey](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@stuvey](https://forums.plex.tv/u/stuvey)\
**Post date:** [September 3, 2026, 6:34pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/14 "2026-09-03T18:34:00Z")

</div>

Thanks, I can see now that I missed that email. Your team has probably thought of all this, but just in case:

I hope you’ll keep sending out nags for 1.42.3 to those who haven’t upgraded.

I’d recommend adding a highly visible section to the email about the repo change for those whom your records show make use of your .debs.

I’d also recommend returning a 404 for the outdated repo so folks who missed the March email (like me) will see apt-get update failures, which will lead them to the issue.

Thanks again for the help!

---

<div class="post-metadata">

**Author:** ![valentinlobstein](https://avatars.discourse-cdn.com/v4/letter/v/b487fb/32.png) [@valentinlobstein](https://forums.plex.tv/u/valentinlobstein)\
**Post date:** [September 4, 2026, 1:12pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/15 "2026-09-04T13:12:13Z")

</div>

Posting here since the announcement thread is closed for replies.

Two things on [Important Security Update for Plex Media Server v1.43.2 and earlier](https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319).

**1. The Linux instructions still reference a 2020 build.**

> `sudo dpkg -i plexmediaserver_1.19.4.2935-79e214ead_amd64.deb`

That is the example given in an advisory asking everyone to move to 1.43.3, and someone will copy it verbatim. Worth correcting.

**2. On the CVEs.**

> CVEs have been requested and we’ll reply to this thread with more details once they’re published.

Is there a rough timeline? Until identifiers exist there is nothing for vulnerability management tooling to key on, so anyone who does not read this forum has no way of learning they are affected. That is the part that matters for people running this in front of a network.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [September 4, 2026, 8:14pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/16 "2026-09-04T20:14:41Z")

</div>

A post was split to a new topic: [Synology 418play (INTEL Celeron J3355) of 1.43.3.10896 install issue](https://forums.plex.tv/t/synology-418play-intel-celeron-j3355-of-1-43-3-10896-install-issue/942555)

---

<div class="post-metadata">

**Author:** ![Mogul345](https://avatars.discourse-cdn.com/v4/letter/m/7ea924/32.png) [@Mogul345](https://forums.plex.tv/u/Mogul345)\
**Post date:** [September 7, 2026, 3:45pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/18 "2026-09-07T15:45:22Z")

</div>

Any updates on the desktop flatpak? I just checked Flathub and it’s still 1.112.0. Should I try the snap again if this is truly a critical CVE?

---

<div class="post-metadata">

**Author:** ![Cphusion](https://avatars.discourse-cdn.com/v4/letter/c/58956e/32.png) [@Cphusion](https://forums.plex.tv/u/Cphusion)\
**Post date:** [September 8, 2026, 4:26pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/19 "2026-09-08T16:26:42Z")

</div>

An updates on this, it’s almost been a week?

---

<div class="post-metadata">

**Author:** ![dane22](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dane22/32/4389_2.png) [@dane22](https://forums.plex.tv/u/dane22)\
**Post date:** [September 8, 2026, 5:47pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/20 "2026-09-08T17:47:08Z")

</div>

Nothing yet, sorry

---

<div class="post-metadata">

**Author:** ![itsamezachary](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/itsamezachary/32/122376_2.png) [@itsamezachary](https://forums.plex.tv/u/itsamezachary)\
**Post date:** [September 8, 2026, 10:29pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/21 "2026-09-08T22:29:24Z")

</div>

I’ve been wondering about that Flatpak runtime bit. I noticed it a while ago when looking at permissions for my Flatpak packages in Flatseal. I didn’t know if it was a concern or not.

As for the CVE, this has pushed me to disable remote access on my Plex server. I have a VPN connection to the network, and I’m beginning to think that multiple holes in the network are an unnecessary danger. AI-enabled hacks, and CVE’s are becoming an every day thing in my news feeds.

---

<div class="post-metadata">

**Author:** ![Cphusion](https://avatars.discourse-cdn.com/v4/letter/c/58956e/32.png) [@Cphusion](https://forums.plex.tv/u/Cphusion)\
**Post date:** [September 14, 2026, 6:08pm UTC](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438/22 "2026-09-14T18:08:10Z")

</div>

Seems the Flatpak has been updated, finally!

> [@Plex (tv.plex.PlexDesktop) version 1.110.0 \[flatpak\] needs updating](https://forums.plex.tv/t/plex-tv-plex-plexdesktop-version-1-110-0-flatpak-needs-updating/931945/93):
>
> FYI… version 1.115.0 has arrived on flathub [https://flathub.org/en/apps/tv.plex.PlexDesktop](https://flathub.org/en/apps/tv.plex.PlexDesktop)

Thanks @PlexTV staff

[Next page](https://forums.plex.tv/t/plextv-staff-about-the-recent-security-update/942438.md?page=2)
