Plex Patch Requires Both Sides to Move

Plex told users to update its desktop clients and Media Server immediately after finding multiple security vulnerabilities, including CVE-2020-5741. The notice covers both components, not just the server side. The practical catch is version drift: if one side gets patched and the other stays behind, the older component can still be reachable. In mixed deployments, updating the server alone does not clear the exposure if the desktop clients are still on the vulnerable build, or the other way around. For shops that manage Plex clients and servers separately, the security state now depends on both being moved together. The remaining risk is not a new attack path, but a partially patched estate that looks finished from one console and is still open from the other.

Part of the PlainSec briefing for 2026-09-03

Editions

CVEs

Sources