AlphaTheta, the company the entire world still knows as “Pioneer,” has announced a major security vulnerability in many CDJ and XDJ models and all Rekordbox software for macOS, Windows, Android, and iOS. You should definitely patch your software, but what does this mean, exactly, and who’s affected? (Hint: it’s only an issue if you’re connected to a network.)

Updates, fixes, and info

First. the short answer is: update firmware and apps as patches become available, don’t put critical files on a USB stick you’re DJing with (I mean, don’t do that anyway), and don’t connect Rekordbox on insecure and/or public networks.

Fixes from AlphaTheta are already there for some hardware and “partially” fixed for desktop software. Here’s where to find the information:

AlphaTheta’s announcement of the vulnerability:

Important Notice: Security Vulnerability in PRO DJ LINK

Current updated status: PRO DJ LINK vulnerability response status

Detailed product list

In Rekordbox, the easiest way to apply the patch is to update directly in the software. Yes, folks, it’s finally time to actually install the update instead of clicking past it!

rekordbox update manager dialog prompting for 7.2.17 update, in front of "Important Notice: Please update rekordbox to the latest version."

How bad is this?

The vulnerability itself is bad if exposed — that is, if a hacker has access to the network you’re using. Because PRO DJ LINK is effectively a server (NTS), the vulnerability could potentially expose files on your USB stick or SD card on a connected CDJ/XDJ — or files on your computer on a Mac or Windows PC running Rekordbox.

I expect we’re actually overstating how many people are impacted, because — frankly, a lot of DJs don’t like, trust, or know how to use a lot of these new networked features. But now they’re kind of proven right, anyway. USB sticks were easy to understand: someone could steal your USB stick, so you wouldn’t include files you were worried about. Networks are another matter, once they become public, and more than just a local Ethernet cable.

See below for more on the specifics.

TL:DR — this is an issue only because of networked DJ gear. This is not a problem for the standard DJ use case as we’ve known it. Connecting players on a closed network? Fine. Loading your music on a USB stick and sticking it into a player on that closed network? No problem. The vulnerability requires that someone be connected to the same network.

Who discovered this

Triode, aka San Francisco-based DJ, producer, and developer “Chris L,” reported the vulnerability to Pio–AlphaTheta. (It’s time to follow him on Twitch!)

Here’s his full explanation [emphasis mine]:

PRO DJ LINK transfers music files with an NFS server. In rekordbox this NFS server is started when you enable Link Export mode. On hardware like a CDJ-3000 or XDJ-AZ the NFS server is started when you boot up the player.

The NFS server allows you to specify any file path. In rekordbox that means you can download any file on the hard drive. On hardware, it’s any file on your USB stick. On mobile devices, it’s any file that is inside the Secure Enclave.

The NFS server has authentication but it’s a hardcoded value you add to the NFS header.

There’s a patch for Rekordbox so download the latest version. A patch for Android and IOS apps is coming soon. Firmware updates for all-in-ones, and players are also coming.

I’ll release the code once AlphaTheta has fully patched the vulnerabilities.

In the mean time, make sure you’re not putting important files in your USB stick, and only use PRO DJ LINK when you need it.

What it actually means

No, this is not “all CDJs” — but it is a lot of gear and all of the software (potentially). XDJ-700, XDJ-1000MK2, CDJ-900NXS2, CDJ-2000NXS2, CDJ-3000, and CDJ-3000X are all impacted. DJM mixers are not. Many all-in-ones are, including the OMNIS-DUO, XDJ-RX2/3, XDJ-RR, and XDJ-XZ. One I hadn’t thought of: even the RMX-IGNITE requires a fix. (Most older hardware and hardware outside the XDJ/CDJ line is unaffected.)

Rekordbox v6-7 for Windows and macOS, as well as mobile versions for iOS and Android, are affected. Stagehand and PRO DJ LINK Bridge are not.

See the full list. What isn’t on the list is as relevant as what is, because it indicates that this vulnerability was added to networked devices as a new “feature.”

This is a significant security flaw—but it affects one specific use case. This is a little confusing, because of typical AlphaTheta technobabble. PRO DJ LINK is the connection between gear. That’s what most of us know as the Ethernet cable we run between CDJs and XDJs to sync them up. There’s been no problem with that system whatsoever, because to access any security vulnerability, you would need to physically connect an Ethernet cable and hub to the network with the players.

Likewise, if you’ve just been plugging a USB drive into your computer or hub and using Sync Manager to load files, you’re not using the affected functionality. It’s not Sync Manager but the WiFi connection:

WiFi icon highlighted, with "Searches for a device with which to establish a connection via Wi-Fi"

LINK EXPORT works when you connect to an AlphaTheta DJ player or your mobile device running Rekordbox. It’s not even a well-documented feature. It really feels like AlphaTheta’s MCAS moment: a feature that, on its own, worked as engineered, but lacked proper safety precautions and documentation.

See above emphasis: newer AlphaTheta hardware boots up an NFS server, by default, without prompting you for custom authentication.

How can you protect yourself? Patch your software. But since AlphaTheta notes that it has only a “partial” fix, an easy solution is just don’t connect to the players on an open network. Make sure your network is secured. Honestly, I’d just skip the networked features and use sneakernet USB sticks. Since players may start up their own file server, don’t trust a network you see in a venue, don’t make an open network available or with easily-guessed passwords (including via hotspots, etc.), and assume that any files on a USB stick could be available.

You should assume that anyway, because the biggest security vulnerability in the club is still “someone walks off with your USB stick.”

Don’t do this, in general

It’s hard not to be critical here. I can understand how it happened: AlphaTheta wanted to make this easy to use, without prior setup. But making a file server publicly available with exposed authentication is pretty reckless.

It’s great that Triode found this issue, and it’s great that AlphaTheta is responding quickly and clearly. But this would be unsafe in any year, and we’re now in 2026, with armies of AI-empowered swarms coming after every single security vulnerability.

We all have to do better. And I don’t just mean AlphaTheta. We need to start thinking about what’s exposed on public networks, because AI will make it much easier than before to find and exploit vulnerabilities.

And if you want to be really safe, I mean, you can always listen to Bill Adama, as part of a series I call Posting This Clip Until People Get The Message. You’ll see him again. (I mean, if you’re going to network, then check for vulnerabilities.)

The Cylons look like us now — don’t forget.

Previously: