Critical [CVE-2020-14040 +33] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes
This critical-severity Veeam advisory covers CVE-2020-14040 and CVE-2021-23017 and 32 more CVEs.
Android app · Google Play
Monitor future Veeam CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
List of Security Fixes and Improvements in Veeam Kasten for Kubernetes
KB ID: 4825
Product:
Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5
Published: 2026-03-02
Last Modified:
Purpose
This article aims to provide our customers' security and compliance teams with detailed information on security improvements.
- Veeam Kasten for Kubernetes — Release Notes
- Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory
- Upgraded Dex image dependencies to resolve multiple Critical and High CVEs
- Upgraded to the latest UBI base image to resolve multiple CVEs.
- Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities.
- Updated the UBI minimal base image to incorporate the latest security fixes.
- Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out.
- Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs
- Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs
CISA Known Exploited Vulnerability
- Listed:
- Oct 9, 2025 · federal remediation due Oct 30, 2025
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware use:
- Unknown
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
- 8.5.10
- 8.5.5
- 1.26.1
- 8.5.3
- 1.25.7
- 8.5.1
- 1.25.6
- 8.0.15
- 1.25.5
- 8.0.11
- 1.25.3
- 46.0
- 8.0.8
- 1.24.7
- 1.24.6
- 1.24.5
- 1.24.4
- 1.24.3
- 1.23.8
- 7.5.5
- 1.23.7
- 1.23.6
- 1.22.5
- 7.0.1
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Mitigation checklist
- List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Veeam Kasten for Kubernetes | 7 | 7.5 | 8 | 8.5 Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: 2026-08-14 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Kasten for Kubernetes.
- It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out.
- Mitigation: Configure a bucket-level Default Object Lock retention so the object store stamps new objects at write time, or upgrade to Kasten 8.5.10.
- Veeam Kasten for Kubernetes 8.5.5 Upgrade to Go 1.26.1 to address CVE-2026-25679 and CVE-2026-27142 Updated the UBI base image to address CVE-2026-4111 Veeam Kasten for Kubernetes 8.5.3 Upgrade to Go 1.25.7 to address CVE-2025-61732.
- Veeam Kasten for Kubernetes 8.5.1 Upgrade to Go 1.25.6 to address CVEs: CVE-2025-61726 CVE-2025-61728 CVE-2025-61731 CVE-2025-68119 CVE-2025-68121 Updated base image used to build Veeam Kasten container images to pull in latest security updates.
- Veeam Kasten for Kubernetes 8.0.15 Upgrade to Go 1.25.5 to address CVE-2025-61727 and CVE-2025-61729.
- It is recommended to upgrade Veeam Kasten to get this fix.
- Veeam Kasten for Kubernetes 8.0.11 Upgrade to Go 1.25.3 to mitigate security vulnerabilities.
- Veeam Kasten for Kubernetes 8.0.14 Improved logging security for specific block mode datamover upload Pod invocations.
Official advisory · high-confidence parse· fetched 2 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.