Plex Leaves Thousands Exposed to Old Bugs

BleepingComputer says more than 36,000 Plex Media Server instances are still exposed online and unpatched against recent vulnerabilities, including CVE-2020-5741, which is already on CISA’s Known Exploited Vulnerabilities list. The report also flags CVE-2025-34158 among the affected issues. The problem is not a new attack trick so much as a long-lived remediation gap: servers reachable from the internet are still sitting on bugs that attackers can target remotely. If a Plex box is left exposed, the blast radius is the host itself, not just the media library it serves. For administrators running Plex on the public internet, the story is about persistent footholds that stay reachable until the server is actually brought current. The open question is not whether the flaws exist; it is how many exposed installations are still carrying a known exploitable bug years after disclosure.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: Plex Leaves Thousands Exposed to Old Bugs

CVEs

Sources