Multiple Denial-of-Service Vulnerabilities in Backblaze Backup Software
Article Content
Five vulnerabilities (ZDI-26-624, ZDI-26-625, ZDI-26-626, ZDI-26-627, ZDI-26-628) have been identified in Backblaze Personal Computer Backup, allowing local attackers to create a denial-of-service condition. Exploitation requires low-privileged code execution on the target system, where attackers can create symbolic links to overwrite arbitrary files. All vulnerabilities were reported to the vendor on April 7, 2026, and have been patched in Release Version 10.0.1.1069. The coordinated public release of advisories occurred on September 9, 2026, with updates provided on the same day. Users of Backblaze Personal Computer Backup are urged to update to the latest version to mitigate these risks.
Key Points: • Five vulnerabilities in Backblaze Personal Computer Backup allow for denial-of-service attacks. • Exploitation requires local access and low-privileged code execution. • All vulnerabilities have been patched in version 10.0.1.1069.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.