36,000 Plex Servers Found Exposed to Potential Risks
The Shadowserver Foundation identified thousands of internet-facing servers running outdated software susceptible to security flaws.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust automatic updates to keep your internet-connected devices secure without manual verification?
Security researchers identified 36,000 internet-exposed Plex Media Server instances running versions vulnerable to security flaws. Plex issued a warning on September 1, 2026, though there is currently no evidence that these specific vulnerabilities are being actively exploited.
Why it matters
This gap highlights the lag between the release of critical security patches and their application by administrators of internet-facing services. Continuous scanning helps organizations and users understand the real-world exposure of systems that remain on outdated software versions.
The Shadowserver Foundation identified servers running version 1.43.2 and earlier of the Plex Media Server software. Security patches require moving to at least version 1.43.3, while the latest available release as of September 10 is version 1.43.4.10903.
The players
Plex
A developer of media server software that enables users to stream personal media collections across home and internet-connected devices.
The Shadowserver Foundation
A security organization that provides threat intelligence by scanning the internet to identify vulnerable infrastructure and malware activity.
The details
The Shadowserver Foundation performed internet scans to identify instances of the Plex software that were exposed to the public web. By querying the version headers of these reachable systems, they mapped which servers were still running software versions that contain known vulnerabilities. Administrators can resolve these risks by manually updating their installations to the current version provided by the manufacturer.
Timeline
September 1, 2026: Plex issued an initial security warning to users.
September 4, 2026: The Shadowserver Foundation began scanning for vulnerable systems.
September 9, 2026: Researchers confirmed 36,000 exposed Plex instances.
September 10, 2026: Plex released version 1.43.4.10903 to address security gaps.
The Tech Race
This incident follows the precedent set by mass-scanning events like the 2021 Kaseya VSA ransomware attack, which underscored the danger of internet-exposed management software. The current situation highlights the ongoing industry challenge of ensuring that distributed, self-hosted infrastructure remains patched against newly disclosed vulnerabilities.
Users running personal Plex Media Servers should verify their current version and update to the latest release to ensure known vulnerabilities are mitigated. The update must be performed manually by administrators for each instance that is exposed to the internet.
The takeaway
This discovery serves as a reminder to audit the software versions of all exposed media hardware. Users should monitor official manufacturer security bulletins to identify when updates are released for their specific deployment environment.
Further reading
For broader trends in infrastructure security and patch management, see the Cybersecurity section.
Source note: This article includes information reported by ESecurityPlanet.
Live Poll
Do you trust automatic updates to keep your internet-connected devices secure without manual verification?






