Over 36,000 exposed Plex servers vulnerable to recent flaws
-
Over 36,000 Plex Media servers exposed to the internet are still running unpatched versions, leaving them susceptible to recently disclosed security vulnerabilities. The affected servers are believed to be reachable without authentication, which significantly increases the risk of exploitation.
The flaws in question allow attackers to potentially compromise the media server, gaining access to sensitive user data or deploying malicious code. While the exact attack vectors vary, the core issue stems from improper handling of certain requests, which could lead to remote code execution or information disclosure.
- Affected component: Plex Media Server
- Exposure: Publicly accessible instances
- Risk: Remote exploitation without requiring user credentials
Administrators are strongly advised to update their Plex Media Server installations to the latest available version immediately. It is also recommended to restrict remote access to trusted networks or users, and to review server logs for any signs of unauthorized activity. Given the significant number of unpatched systems, this remains a high-priority threat for anyone running a self-hosted Plex setup.
Source: BleepingComputer
With over 36,000 exposed instances, is your organization or personal setup among those still waiting on a patch, and what steps are you taking to secure your media server in the meantime?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login