rekordbox 7.2.17 shipped July 30, 2026. One line under security: “Enhanced LINK EXPORT security.” Nine days later came the explanation.
Their official notice, dated August 8, 2026, confirmed a vulnerability in the PRO DJ LINK protocol. The exposure: once someone else reaches the same PRO DJ LINK network, the files on connected USB drives and SD cards in CDJ and XDJ units — and data on any Windows PC or Mac sharing that segment — are visible to them. No incidents of harm have been reported.
What the vulnerability means in practice
This is a local network attack. An attacker needs to already be on the same PRO DJ LINK network as your gear — remote exploitation over the internet is not in scope.
The official notice describes read access — a third party on the network can view data on connected storage. AlphaTheta withheld technical specifics at disclosure, standard practice while fixes were in progress, so exactly what’s accessible on a connected PC or Mac wasn’t published. Write or delete access isn’t mentioned.
For a bedroom setup on a home router, the practical risk is low. A shared venue network is another matter. If CDJ or XDJ units connect to the same router as a front-of-house system, bar tablets, or an open guest network, any other device on that segment can exploit it. The attack is then whether anyone on that network is looking. A dedicated isolated booth network removes that exposure; most clubs can’t confirm they have one.
Which hardware is affected
The affected CDJ and XDJ models are:
- CDJ-3000X
- CDJ-3000
- CDJ-2000NXS2
- CDJ-1500X
- CDJ-900NXS
- XDJ-1000MK2
- XDJ-700
- XDJ-AZ
- XDJ-XZ
DJM mixers are not affected — the vulnerability is in the PRO DJ LINK layer, not the mixer. rekordbox for iOS and Android is also on the affected list.
The model list comes from Digital DJ Tips’ coverage of the advisory (August 10, 2026). AlphaTheta’s own notice says “certain CDJ/XDJ models” — no inline list. Check the AlphaTheta support pages for your specific model before assuming you’re in the clear.
The patch — and why the timing matters
rekordbox 7.2.17 is the patched version for users on the v7 branch. It shipped July 30. If you’ve updated since then, you’re covered on the software side. The current release as of late September 2026 is 7.2.19 (September 24) — updating to the latest gets you the security fix and subsequent work on Spotify compatibility and SoundSwitch support.
If you’re on rekordbox 6, the notice confirms the v6 branch is patched — no specific version number given. Update to the current v6 release and verify against the AlphaTheta security notice.
Hardware firmware for affected CDJ and XDJ units had not been released as of publication. AlphaTheta’s tracking page at support.alphatheta.com lists per-model updates as they land. Check it before your next venue gig.
AlphaTheta patched on July 30 and disclosed publicly on August 8. By the time most DJs saw the vulnerability report, the fix had been live nine days. That gap was deliberate — patch first, announce after. Standard responsible disclosure. Anyone keeping rekordbox current was protected before the story broke.
What to do
Four steps, in order:
- Update rekordbox. Minimum 7.2.17; 7.2.19 is current. v6 users: update to the latest v6 release — see the AlphaTheta security notice for confirmation.
- Check your hardware firmware. No firmware patches for CDJ and XDJ units had been released as of publication. Monitor the AlphaTheta tracking page at support.alphatheta.com for updates as they land.
- Review what’s on your performance USB. Contracts, payment details, personal files — none of these belong on a drive that connects to a venue network. Library tracks only.
- Ask about the booth network at venues. Most venues won’t know offhand — a booth on a dedicated VLAN or isolated router isn’t exposed to other guests on the venue’s main Wi-Fi. Worth asking.
Ohm records from the mixer’s USB audio output, not over the PRO DJ LINK network, so the recording workflow is unaffected. For how that audio path works, see How Ohm Routes Post-Fader Audio From Your DJM Mixer.
The software fix is done. Hardware firmware is still the open question. Until it lands for your players, treat shared venue Wi-Fi as untrusted — good network hygiene regardless of any specific vulnerability.



