Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
KNOWLEDGE BASE ARTICLEVEEAMVERIFIED

PUBLISHER UPDATE · KB4825

KB4825 release notes and known issues

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

Scope: Veeam products. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Veeam Kasten for Kubernetes | 7 | 7.5 | 8 | 8.5 | 9 Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: 2026-09-14 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Kasten for Kubernetes . This article aims to provide our customers' security and compliance teams with detailed information on security improvements. Full product release notes are available here: Veeam Kasten for Kubernetes — Release Notes Security Fixes and Improvements Veeam Kasten for Kubernetes 9.0.5 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Updated the Go runtime to resolve additional upstream Go CVEs. Updated the bundled Prometheus Helm chart to resolve security issues. Veeam Kasten for Kubernetes 9.0.4 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Patched go-ntlmssp in the Dex component to resolve CVE-2026-32952. Updated the Go runtime and golang.org/x/mod dependency to resolve CVE-2026-56865 and additional upstream Go CVEs. Veeam Kasten for Kubernetes 9.0.3 Upgraded go-git to resolve CVE-2026-71556 Upgraded the configmap-reload sidecar to resolve CVE-2026-56852 Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory Upgraded Dex image dependencies to resolve multiple Critical and High CVEs Veeam Kasten for Kubernetes 9.0.2 Upgraded to the latest UBI base image to resolve multiple CVEs. Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. Veeam Kasten for Kubernetes 9.0.1 Upgraded to Go 1.26.5 to resolve CVE-2026-39822 & CVE-2026-42505 Updated the UBI minimal base image to incorporate the latest security fixes. Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out . Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs Veeam Kasten for Kubernetes 8.5.13 Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs Veeam Kasten for Kubernetes 8.5.12 Upgraded to the latest UBI base image to resolve CVE-2026-45186 and CVE-2026-45447 Upgraded to Go 1.26.4 to resolve CVE-2026-42504 Kasten Multi-cluster Permissions : Hardened multi-cluster security by tightening the permissions granted to the impersonation `ClusterRole` on managed secondary clusters and removing sensitive token values from debug logs. Veeam Kasten for Kubernetes 8.5.10 Upgraded to latest UBI base image to resolve CVE-2026-40356 and CVE-2026-4878 Immutability regression in Kasten 8.5.1–8.5.9 (S3 / GCS / Azure) Newly written backup objects were not stamped with a retain-until date at write time and remained deletable until the Blob Lifecycle Manager applied protection on its next refresh cycle. A user, script, or attacker with bucket delete permissions could permanently delete those objects during this window, potentially rendering the affected restore points unrecoverable. Mitigation: Configure a bucket-level Default Object Lock retention so the object store stamps new objects at write time, or upgrade to Kasten 8.5.10. Veeam Kasten for Kubernetes 8.5.5 Upgrade to Go 1.26.1 to address CVE-2026-25679 and CVE-2026-27142 Updated the UBI base image to address CVE-2026-4111 Veeam Kasten for Kubernetes 8.5.3 Upgrade to Go 1.25.7 to address CVE-2025-61732 . Veeam Kasten for Kubernetes 8.5.2 Updated base image used to build Veeam Kasten container images to pull in latest security updates. Veeam Kasten for Kubernetes 8.5.1 Upgrade to Go 1.25.6 to address CVEs: CVE-2025-61726 CVE-2025-61728 CVE-2025-61731 CVE-2025-68119 CVE-2025-68121 Updated base image used to build Veeam Kasten container imag

Improvements and security content

  • List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Veeam Kasten for Kubernetes | 7 | 7.5 | 8 | 8.5 | 9 Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: 2026-09-14 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Kasten for Kubernetes . This article aims to provide our customers' security and compliance teams with detailed information on security improvements. Full product release notes are available here: Veeam Kasten for Kubernetes — Release Notes Security Fixes and Improvements Veeam Kasten for Kubernetes 9.0.5 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Updated the Go runtime to resolve additional upstream Go CVEs. Updated the bundled Prometheus Helm chart to resolve security issues. Veeam Kasten for Kubernetes 9.0.4 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Patched go-ntlmssp in the Dex component to resolve CVE-2026-32952. Updated the Go runtime and golang.org/x/mod dependency to resolve CVE-2026-56865 and additional upstream Go CVEs. Veeam Kasten for Kubernetes 9.0.3 Upgraded go-git to resolve CVE-2026-71556 Upgraded the configmap-reload sidecar to resolve CVE-2026-56852 Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory Upgraded Dex image dependencies to resolve multiple Critical and High CVEs Veeam Kasten for Kubernetes 9.0.2 Upgraded to the latest UBI base image to resolve multiple CVEs. Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. Veeam Kasten for Kubernetes 9.0.1 Upgraded to Go 1.26.5 to resolve CVE-2026-39822 & CVE-2026-42505 Updated the UBI minimal base image to incorporate the latest security fixes. Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out . Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs Veeam Kasten for Kubernetes 8.5.13 Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs Veeam Kasten for Kubernetes 8.5.12 Upgraded to the latest UBI base image to resolve CVE-2026-45186 and CVE-2026-45447 Upgraded to Go 1.26.4 to resolve CVE-2026-42504 Kasten Multi-cluster Permissions : Hardened multi-cluster security by tightening the permissions granted to the impersonation `ClusterRole` on managed secondary clusters and removing sensitive token values from debug logs. Veeam Kasten for Kubernetes 8.5.10 Upgraded to latest UBI base image to resolve CVE-2026-40356 and CVE-2026-4878 Immutability regression in Kasten 8.5.1–8.5.9 (S3 / GCS / Azure) Newly written backup objects were not stamped with a retain-until date at write time and remained deletable until the Blob Lifecycle Manager applied protection on its next refresh cycle. A user, script, or attacker with bucket delete permissions could permanently delete those objects during this window, potentially rendering the affected restore points unrecoverable. Mitigation: Configure a bucket-level Default Object Lock retention so the object store stamps new objects at write time, or upgrade to Kasten 8.5.10. Veeam Kasten for Kubernetes 8.5.5 Upgrade to Go 1.26.1 to address CVE-2026-25679 and CVE-2026-27142 Updated the UBI base image to address CVE-2026-4111 Veeam Kasten for Kubernetes 8.5.3 Upgrade to Go 1.25.7 to address CVE-2025-61732 . Veeam Kasten for Kubernetes 8.5.2 Updated base image used to build Veeam Kasten container images to pull in latest security updates. Veeam Kasten for Kubernetes 8.5.1 Upgrade to Go 1.25.6 to address CVEs: CVE-2025-61726 CVE-2025-61728 CVE-2025-61731 CVE-2025-68119 CVE-2025-68121 Updated base image used to build Veeam Kasten container imag

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Veeam products

Affected versions

  • 7.5
  • 8.5
  • 5.5
  • 6.5
  • 9.0.5
  • 9.0.4
  • 9.0.3
  • 9.0.2
  • 9.0.1
  • 1.26.5
  • 8.5.13
  • 8.5.12
  • 1.26.4
  • 8.5.10
  • 8.5.1
  • 8.5.9
  • 8.5.5
  • 1.26.1
  • 8.5.3
  • 1.25.7
  • 8.5.2
  • 1.25.6

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

VEEAMVERIFIED

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source