AlphaTheta, the company the entire world still knows as “Pioneer,” has announced a major “security vulnerability” in many CDJ and XDJ models and all Rekordbox software for macOS, Windows, Android, and iOS. You should definitely patch your software, but what does this mean, exactly, and who’s affected?
Updates, fixes, and info
First. the short answer is: update firmware and apps as patches become available. Fixes from AlphaTheta are already there for some hardware and “partially” fixed for desktop software. Here’s where to find the information:
AlphaTheta’s announcement of the vulnerability:
Important Notice: Security Vulnerability in PRO DJ LINK
Current updated status: PRO DJ LINK vulnerability response status
Detailed product list
In Rekordbox, the easiest way to apply the patch is to update directly in the software. Yes, folks, it’s finally time to actually install the update instead of clicking past it!

How bad is this?
So, it’s bad. Because PRO DJ LINK is effectively a server (NTS), the vulnerability could potentially expose all the files on your USB stick or SD card on a connected CDJ/XDJ — or files on your computer on a Mac or Windows PC running Rekordbox. A hacker would only need access to the WiFi network. (If there’s no network, in contrast, you’re fine.)
This should be your latest reminder to keep WiFi networks secure with strong passwords, and to never put sensitive files on a USB stick you’re using for DJing. But this is also a pretty unacceptable security flaw from AlphaTheta.
See below for more on the specifics.
TL:DR: This is not an issue for the standard CDJ use case as we’ve known it. Connecting players on a closed network? Fine. Loading your music on a USB stick and sticking it into a player on that closed network? No problem. But AlphaTheta has “fixed” that functionality by providing insecure file hosting by default on newer players like the CDJ-3000. And likewise, networked export from desktop and mobile is now a really bad idea. Full details below.
Who discovered this
Triode, aka San Francisco-based DJ, producer, and developer “Chris L,” reported the vulnerability to Pio–AlphaTheta. (It’s time to follow him on Twitch!)
Here’s his full explanation [emphasis mine]:
PRO DJ LINK transfers music files with an NFS server. In rekordbox this NFS server is started when you enable Link Export mode. On hardware like a CDJ-3000 or XDJ-AZ the NFS server is started when you boot up the player.
The NFS server allows you to specify any file path. In rekordbox that means you can download any file on the hard drive. On hardware, it’s any file on your USB stick. On mobile devices, it’s any file that is inside the Secure Enclave.
The NFS server has authentication but it’s a hardcoded value you add to the NFS header.
There’s a patch for Rekordbox so download the latest version. A patch for Android and IOS apps is coming soon. Firmware updates for all-in-ones, and players are also coming.
I’ll release the code once AlphaTheta has fully patched the vulnerabilities.
In the mean time, make sure you’re not putting important files in your USB stick, and only use PRO DJ LINK when you need it.
What it actually means
No, this is not “all CDJs” — but it is a lot of gear and all of the software (potentially). XDJ-700, XDJ-1000MK2, CDJ-900NXS2, CDJ-2000NXS2, CDJ-3000, and CDJ-3000X are all impacted. DJM mixers are not. Many all-in-ones are, including the OMNIS-DUO, XDJ-RX2/3, XDJ-RR, and XDJ-XZ. One I hadn’t thought of: even the RMX-IGNITE requires a fix. (Most older hardware and hardware outside the XDJ/CDJ line is unaffected.)
Rekordbox v6-7 for Windows and macOS, and mobile versions for iOS and Android, are impacted. Stagehand and PRO DJ LINK Bridge are not.
See the full list. What isn’t on the list is as relevant as what is, because it indicates that this was a vulnerability added to networked devices as a new “feature.”
This is a huge security flaw—but it affects one specific use case. This is a little confusing, because of typical AlphaTheta technobabble. PRO DJ LINK is the connection between gear. That’s what most of us know as the Ethernet cable we run between CDJs and XDJs to sync them up. There’s been no problem with that system whatsoever, because to access any security vulnerability, you would need to physically connect an Ethernet cable and hub to the network with the players.
Likewise, if you’ve just been plugging a USB drive into your computer or hub and using Sync Manager to load files, you’re not using the affected functionality.

It’s only when you make the PRO DJ LINK network accessible that you have an issue. That’s LINK EXPORT: the idea was, you’d make files accessible over the wide area network via cabled or wireless connection, from your computer or the hardware.
LINK EXPORT works when you connect to an AlphaTheta DJ player or your mobile device running Rekordbox. It’s not even a well-documented feature. It really feels like AlphaTheta’s MCAS moment: a feature that, on its own, worked as engineered, but lacked proper safety precautions and documentation.
See above emphasis: newer AlphaTheta hardware boots up an NFS server, by default, without prompting you for custom authentication.
How can you protect yourself? Patch your software. But since AlphaTheta notes that it has only a “partial” fix, an easy solution is just don’t connect to the players on an open network. Make sure your network is secured. Honestly, I’d just skip the networked features and use sneakernet USB sticks. Since players may start up their own file server, don’t trust a network you see in a venue, don’t make an open network available or with easily-guessed passwords (including via hotspots, etc.), and assume that any files on a USB stick could be available.
You should assume that anyway, because the biggest security vulnerability in the club is still “someone walks off with your USB stick.”
Don’t do this
It’s hard not to be critical here. I can understand how it happened: AlphaTheta wanted to make this easy to use, without prior setup. But making a file server publicly available with exposed authentication is pretty reckless.
For many DJs, it’s also another example of AlphaTheta’s networked features being a solution in search of a problem — and now one that creates new problems.
It’s great that Triode found this issue, and it’s great that AlphaTheta is responding quickly and clearly. But this would be unsafe in any year, and we’re now in 2026, with armies of AI-empowered swarms coming after every single security vulnerability.
We all have to do better.
And if you want to be really safe, I mean, you can always listen to Bill Adama, as part of a series I call Posting This Clip Until People Get The Message. You’ll see him again. (I mean, if you’re going to network, then check for vulnerabilities.)
The Cylons look like us now — don’t forget.
Previously: