ThreatCluster

Multiple Denial-of-Service Vulnerabilities in Backblaze Backup Software

First seen 9 Sep 2026, 22:13 UTC Zerodayinitiativewww.backblaze.comwww.cve.org 31

Article Content

Browse articles
ThreatCluster

Five vulnerabilities (ZDI-26-624, ZDI-26-625, ZDI-26-626, ZDI-26-627, ZDI-26-628) have been identified in Backblaze Personal Computer Backup, allowing local attackers to create a denial-of-service condition. Exploitation requires low-privileged code execution on the target system, where attackers can create symbolic links to overwrite arbitrary files. All vulnerabilities were reported to the vendor on April 7, 2026, and have been patched in Release Version 10.0.1.1069. The coordinated public release of advisories occurred on September 9, 2026, with updates provided on the same day. Users of Backblaze Personal Computer Backup are urged to update to the latest version to mitigate these risks.

Key Points: • Five vulnerabilities in Backblaze Personal Computer Backup allow for denial-of-service attacks. • Exploitation requires local access and low-privileged code execution. • All vulnerabilities have been patched in version 10.0.1.1069.

Ask AI about this cluster

Timeline

2026-04-07
Vulnerabilities reported to vendor
Five vulnerabilities affecting Backblaze Personal Computer Backup were reported to the vendor.
Zerodayinitiative
2026-04-07
Patch released
Backblaze released version 10.0.1.1069 to address the reported vulnerabilities.
Zerodayinitiative
2026-09-09
Coordinated public release of advisories
Advisories for the vulnerabilities were publicly released, informing users of the risks.
Zerodayinitiative