Got a quiet ping from a reader at half eleven: “Plex says update for security. Is this one of those panic emails or am I actually meant to stop watching and patch the NAS?â€
Fair question. Most of the time those banners are boring. This one isn’t a feature tease. On 1 September 2026, Plex’s own staff account posted an announcement urging server owners and Desktop users to move to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 because they fixed “a number of security issues.†CVEs have been requested. Public CVE write-ups were still not out when I checked, which is exactly why you don’t wait for a dramatic headline before you click Update.
I’m writing this as someone who still runs Plex at home (I already admitted I stuck with Plex over Jellyfin for my own library). If your box is on 1.43.2 or older, treat tonight as patch night. Not next weekend.
What Plex actually said
The official thread is titled “Important Security Update for Plex Media Server v1.43.2 and earlier.†Author: PlexInfo. Tone: blunt.
Key points, without the forum fluff:
Update Plex Media Server to 1.43.3 or newer.
Update Plex Desktop to 1.115.0 if you use that app.
NAS package managers can lag, so you may need a manual install from Plex’s downloads page.
CVEs are requested; more detail later when they’re published.
That’s it. No severity score. No “remote code execution confirmed.†No public exploit walkthrough. The Hacker News write-up from 4 September 2026 matches the same facts: multiple undisclosed flaws, update now, NAS may need a manual package.
When a vendor stays vague on purpose, I don’t invent drama. I also don’t ignore the post. Patch first. Read the CVE notes later with a cup of tea.

How I check my version without guessing
Open your Plex Web UI while signed in as the server owner. Look at Settings for the server, then find the version string. You’re hunting for something like 1.43.3.10896 (or newer). The build I saw on Plex’s public download API tonight was 1.43.3.10896-cb3ebc72d. Numbers move. The rule is simple: if you’re still on 1.43.2 or anything older, you’re behind.
Desktop app is separate. If you watch or manage libraries with Plex Desktop, update that client to 1.115.0 as well. Updating only the phone app on the sofa does nothing for the server sitting in the cupboard.
Windows and Mac (the easy ones)
If automatic updates are on, open the server app and confirm you’re actually on 1.43.3+. Don’t trust the green tick from last month. Look at the version line.
If you’re still old:
1. Go to the official Plex Media Server downloads page.
2. Grab the latest Windows or Mac package.
3. Install over the top. Your libraries usually stay put.
4. Restart if it asks. Open the Web UI. Confirm the version string.
Same idea for Plex Desktop: update the app, don’t assume the server patch covers the desktop binary.
Linux (the bit where people paste the wrong filename)
Plex’s own forum post shows example dpkg / dnf commands with old sample filenames. Do not copy those sample names blindly. Download the current package from the downloads page, then install the file you actually downloaded.
Ubuntu / Debian style: download the .deb, then sudo dpkg -i with that filename.
Fedora / CentOS style: download the .rpm, then install with your package tool using that filename.
Afterward, check the service is running and the Web UI shows 1.43.3+.
NAS owners (this is where updates stall)
Synology, QNAP, Terramaster, WD, Netgear… package centres are often a week behind Plex’s own site. Plex said it out loud: the updated version may not be in the vendor store yet. Manual install is the path.
Rough flow that works on most boxes:
Download the correct NAS package from Plex’s downloads page.
Open your NAS web UI.
Find App Store / App Center / Package Center.
Use Manual Install / Install from file.
Walk the wizard. Let it replace the old Plex Media Server package.
Plex linked vendor help pages for QNAP, Terramaster, WD, Netgear and Synology in that same security thread. If the store still shows 1.43.2, don’t wait for the store icon to turn green. Manual package.
One practical tip from messy real life: screenshot your current version and your library paths before you click. Not because the update usually eats libraries. Because when something odd happens at midnight, you’ll want proof of what you started with.
Docker
If you run the official container, pull a fresh image that includes 1.43.3+ and redeploy the way you normally do. Plex points Docker users at the plexinc/pms-docker README. Don’t half-update a volume and then wonder why the banner still nags.
After recreate, hit the Web UI and read the version. Containers lie if you forget to pull.
NVIDIA Shield note
Plex’s post also says Shield users should open Google Play and install pending updates. That’s client/server packaging on Shield land. Still worth doing if your Shield is the box hosting the server.
What this is not
This is not a call to wipe your library.
This is not proof that your server is already owned.
This is not permission to ignore remote access hardening forever.
While you’re in there, it’s still smart hygiene to keep Remote Access intentional, use a strong Plex account password, and avoid exposing random ports “just because.†I’m not turning this into a full lockdown guide. Update first. Hardening can be tomorrow’s job.
Also: your personal media library is your content. Plex is the organiser and player layer. Same rule I bang on about with IPTV players elsewhere on the site. Tools aren’t a licence. Only keep and stream what you’re allowed to.
If the update goes weird
Some forum threads after 1.43.3 mention client quirks on certain TVs or older NAS models. That’s normal for a wide install base. If the server comes up but a TV app sulks, update that client too, reboot the TV once, then check Plex’s forums for your exact model before you roll back in a panic.
Rolling back for comfort while a security advisory is live is how people stay vulnerable for weeks. Prefer forward fixes unless your specific hardware is genuinely broken and you’ve got a temporary offline plan.
Quick checklist I actually use
Confirm current version in the server Web UI.
Update PMS to 1.43.3+ from official downloads if needed.
Update Plex Desktop to 1.115.0 if you use it.
NAS: manual package if the store lags.
Docker: pull + recreate, then verify version.
Re-check Remote Access still works for the people who should have it.
Only then go back to the film you paused.
If buffering was already a drama before the patch, an update won’t magic your ISP. Test the pipe separately (speedtest.husham.com). Different problem.
I’ve written before about sticking with Plex for my own shelves (Jellyfin vs Plex rant here). That loyalty only works if the server isn’t left on a known-bad build. And if you’re comparing player front-ends for playlists plus libraries, the Lumora notes are over here: Lumora player review.
Bottom line: Plex asked server owners to move to 1.43.3 and Desktop users to 1.115.0. Official source. Multiple security issues. CVE IDs pending. Update, verify the version string, then press play again.
If this stopped you leaving a dusty NAS on 1.43.2, send it to whoever “looks after the media box†in your house. That person is probably you.
YouTube: @husham122
About / contact: www.husham.com/about
Article ID: HUSHAM-20260907-PX43