ZDI publishes five advisories for one CVE-2026-19820 local denial-of-service flaw across five Backblaze Personal Computer Backup components
On 2026-09-09, the Zero Day Initiative published five advisories (ZDI-26-624 through ZDI-26-628), all mapped to CVE-2026-19820 (CVSS 6.1), a local link-following denial-of-service vulnerability affecting the bzbackup, bzserv, bzfilelist, bztransmit, and…
The Zero Day Initiative published five separate advisories on the same day (2026-09-09), each describing a link-following denial-of-service condition in a different component of Backblaze Personal Computer Backup: ZDI-26-624 (bzbackup), ZDI-26-625 (bzserv), ZDI-26-626 (bzfilelist), ZDI-26-627 (bztransmit), and ZDI-26-628 (bzreports). All five advisories are tracked under the single CVE identifier CVE-2026-19820 and carry the same CVSS score of 6.1. In every case, a local attacker must first gain the ability to execute low-privileged code on the target system before triggering the denial-of-service condition via link following. All five source reports are consistent on the CVE identifier, CVSS score, local attack vector, and low-privilege prerequisite; they differ only in which product component each advisory covers. The reports do not state patched versions, fixed releases, vendor statements, or remediation guidance.
- Vulnerability: local link-following denial of service in Backblaze Personal Computer Backup
- CVE identifier: CVE-2026-19820 (same identifier across all five advisories)
- CVSS score: 6.1 (as rated by ZDI)
- ZDI advisory IDs and affected components: ZDI-26-624 (bzbackup), ZDI-26-625 (bzserv), ZDI-26-626 (bzfilelist), ZDI-26-627 (bztransmit), ZDI-26-628 (bzreports)
- Attack prerequisites: attacker must first execute low-privileged code on the target system
- Impact: denial-of-service condition
- Publication date: 2026-09-09 (2026-09-09T05:00:00Z)
- Source: Zero Day Initiative (ZDI) published advisories
Coverage timelineoldest first · each row is one article
- · 6d agoZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability
ZDI Published Advisories· 12
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzserv component of Backblaze Personal Computer Backup.
- · 6d agoZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability
ZDI Published Advisories· 22
ZDI published ZDI-26-627 for a local denial-of-service flaw (CVE-2026-19820, CVSS 6.1) in Backblaze Personal Computer Backup's bztransmit component.
- · 6d agoZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability
ZDI Published Advisories· 22
ZDI published ZDI-26-626 for a local denial-of-service flaw (CVE-2026-19820, CVSS 6.1) in Backblaze Personal Computer Backup's bzfilelist component.
- · 6d agoZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability
ZDI Published Advisories· 12
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzreports component of Backblaze Personal Computer Backup.
- · 6d agoZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability
ZDI Published Advisories· 12
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzbackup component of Backblaze Personal Computer Backup.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19820 | Unbootable-System Denial of Service via Link Following in Backblaze Windows Backup Client CVE-2026-19820 is a link-following flaw (CWE-59) in the Backblaze Personal Computer Backup client for Windows, whose backup components (bzserv, bztransmit, bzfilelist, bzbackup, and bzreports) do not properly resolve links in the folders they traverse. A local user can create a link from Backblaze's folder to Windows OS system files during a backup; when the client follows the link, the affected machine can be rendered unbootable. Successful exploitation requires that an administrator-level system change has removed the specific Windows OS security controls that normally govern link resolution, allowing the link to be planted in this way. The impact is loss of availability of the whole system (high impact on the system's ability to boot), not data theft. Exploitation is not currently known: no public PoC exists, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3%. Do: Update the Backblaze Personal Backup client to the latest vendor release addressing the link-following issues once a fixed version is published (see Backblaze/ZDI advisories ZDI-26-624 through ZDI-26-628). In the meantime, verify that the machine retains the standard Windows security controls around link creation — the flaw requires an administrator-level change that removed them — and restrict which local users can create symlinks or junctions. No in-the-wild exploitation is reported, but monitor Backblaze's advisories for a patched build. | 7.8 | <1% |
| largeroughly hundreds of thousands of Windows installations (Backblaze has historically reported ~500,000+ Computer Backup customers; only Windows systems with the… |