Skip to content
News3 min

AlphaTheta admits a vulnerability in PRO DJ LINK and its patch list leaves the oldest booths out

A third party with access to the PRO DJ LINK network can view the USB drives and SD cards in the player. Models missing from the official table are out of support.

Por Redacción Futura Tickets

Redacción

Respuesta rápida

On 8 August 2026 AlphaTheta published a notice acknowledging a vulnerability in the PRO DJ LINK function of rekordbox and of certain CDJ and XDJ models: a third party who gains unauthorised access to that network can view data on the connected computer or on the USB drives and SD cards inserted in the player. The manufacturer says it is preparing a fix and recommends updating rekordbox (version 7.2.17 or later, or 6.8.7 or later), keeping media with sensitive data off PRO DJ LINK, and connecting the equipment only to password-protected Wi-Fi networks. In the same document it warns that models with PRO DJ LINK that do not appear in its response table have reached end of support.

On 8 August AlphaTheta acknowledged a vulnerability in PRO DJ LINK: anyone who gains unauthorised access to that network can view data on the connected computer and on the player's USB drives and SD cards. A fix is in progress.

The official notice places the flaw in the PRO DJ LINK function of rekordbox and of certain CDJ and XDJ models. It asks users to update rekordbox, to keep media with sensitive data off that network and to use password-protected Wi-Fi only. It says it is not aware of any cases of harm, which is not the same as saying the flaw has not been exploited. No public CVE identifier is on record.

The official table, checked on 14 August and updated by the manufacturer over time, lists as affected, with a fix in progress, the CDJ-3000X, 3000, 2000NXS2, 1500X and 900NXS and the XDJ-1000MK2, 700, AZ and XZ. The DJM-A9, V10, V5 and 900NXS2 mixers are not affected. rekordbox 7 and 6 are listed as only partially fixed, from 7.2.17 or 6.8.7 onwards. The iOS and Android apps are still pending.

Beneath the table sits a line that has not been widely circulated: "Models with PRO DJ LINK functionality not listed below have reached end of support". In other words, anything not shown there is out of support. The end-of-support notice spells out what that means: those models no longer receive security updates. The list includes the CDJ-2000NXS, the CDJ-2000, the 900, the 850, the XDJ-1000 and the DJM-900NXS, the generations that have spent the most years installed in booths. AlphaTheta does not say they are affected. It says something different and sufficient: if they were, there would be no patch.

Three checks. The model and firmware of every player and every mixer, set against the table: the affected unit is the CDJ-900NXS, not the DJM-900NXS2. What is on the USB drives that stay plugged in, the residents' own and the one a guest forgets. And which network the booth is connected to: if it hangs off the venue's network, it shares a segment with the till and the customer Wi-Fi.

The rest of the perimeter is covered in the events security guide. And on third-party decisions that force a production to be rebuilt in days, Tomorrowland's pyrotechnics.

Sources

Share

Preguntas frecuentes

What is the PRO DJ LINK vulnerability and which equipment does it affect?
According to AlphaTheta's notice of 8 August 2026, a third party who gains unauthorised access to a PRO DJ LINK network can view data stored on the connected computer or on the USB drives and SD cards inserted in a CDJ or XDJ. The official table, checked on 14 August, lists as affected, with a fix in progress, the CDJ-3000X, CDJ-3000, CDJ-2000NXS2, CDJ-1500X and CDJ-900NXS and the XDJ-1000MK2, XDJ-700, XDJ-AZ and XDJ-XZ, as well as rekordbox for iOS and Android. The DJM-A9, DJM-V10, DJM-V5 and DJM-900NXS2 mixers are listed as not affected. The manufacturer says it is not aware of any cases of harm to date, which is not the same as stating that the flaw has not been exploited, and no public CVE identifier is on record.
Which version of rekordbox needs to be installed?
The official table gives version 7.2.17 or later for rekordbox Ver. 7 and 6.8.7 or later for rekordbox Ver. 6. The status deserves a careful read: both are listed as only partially fixed, with further updates planned, so updating does not close the matter. The iOS and Android versions are listed as affected, with the fix in progress. The status is as of 14 August 2026 and the manufacturer is updating the document over time.
What can a club do if its CDJs are out of support?
AlphaTheta does not say that equipment out of support is affected by this vulnerability. What it does say, and these are two different things, is that any model with PRO DJ LINK that does not appear in its response table has reached end of support, and that the models on that list no longer receive security updates or support for vulnerabilities. The honest conclusion is that, if they were affected, there would be no patch. With that equipment, the actionable steps are the two mitigations that do not depend on firmware: do not leave USB drives or SD cards with sensitive data in the booth, and connect the equipment only to a password-protected Wi-Fi network.

About the author

Redacción Futura Tickets

Redacción

Elaborado por la Redacción de Futura Tickets con asistencia de IA y revisión editorial humana. Responsable editorial: Alejandro García Cestero. Foto: Novkov Visuals vía Pexels.

¿Quieres ver Futura Tickets en acción?

Los datos que publicamos salen del mismo panel que usan los promotores que venden con nosotros.

Solicitar demo