-
HansMeiser
- Enthusiast
- Posts: 92
- Liked: 14 times
- Joined: Jul 11, 2022 6:59 am
- Contact:
Veeam 12 still Security Fixes?
Hello,
since September 2025 Veeam 12 is in "End of Fix" State. So we cant expect new updates etc., which is fine. But can we expect further security patches that would be necessary in case of a problem?
I wonder if V12 was really not affected by CVE-2025-55125 and CVE-2025-59469 or only V13 was fixed. According to my colleague, no more security patches will be released for v12.
Strictly speaking version 12.3.2.4165 was released on 14. Oct. 2025, so this was already after "End-Of-Fix".
Please help me to understand this situation and classify the dates.
Thanks,
Hans
since September 2025 Veeam 12 is in "End of Fix" State. So we cant expect new updates etc., which is fine. But can we expect further security patches that would be necessary in case of a problem?
I wonder if V12 was really not affected by CVE-2025-55125 and CVE-2025-59469 or only V13 was fixed. According to my colleague, no more security patches will be released for v12.
Strictly speaking version 12.3.2.4165 was released on 14. Oct. 2025, so this was already after "End-Of-Fix".
Please help me to understand this situation and classify the dates.
Thanks,
Hans
-
david.domask
- Veeam Software
- Posts: 3350
- Liked: 785 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Veeam 12 still Security Fixes?
Hi Hans,
>I wonder if V12 was really not affected by CVE-2025-55125 and CVE-2025-59469 or only V13 was fixed
As noted in our KB article, only v13 is affected by these items.
Veeam's Product Life Cycle is defined by main version, and it's best to upgrade to the current version as soon as time allows. Our focus is always on version that have not reached End of Fix. Is there a blocker that prevents you from upgrading to v13?
>I wonder if V12 was really not affected by CVE-2025-55125 and CVE-2025-59469 or only V13 was fixed
As noted in our KB article, only v13 is affected by these items.
Veeam's Product Life Cycle is defined by main version, and it's best to upgrade to the current version as soon as time allows. Our focus is always on version that have not reached End of Fix. Is there a blocker that prevents you from upgrading to v13?
David Domask | Product Management: Principal Analyst
-
HansMeiser
- Enthusiast
- Posts: 92
- Liked: 14 times
- Joined: Jul 11, 2022 6:59 am
- Contact:
Re: Veeam 12 still Security Fixes?
Hello,
we build a new backupsystem in may/jun 2026, preparation are running. The new system will have v13 from the beginning. In my opinion it is only needed to update the current system to v13 if v12 is excluded from security fixes by now.
my mate says end-of-fix also means end-of-security-fixes. if this is true we should upgrade to v13 asap.
Thanks,
Hans
we build a new backupsystem in may/jun 2026, preparation are running. The new system will have v13 from the beginning. In my opinion it is only needed to update the current system to v13 if v12 is excluded from security fixes by now.
my mate says end-of-fix also means end-of-security-fixes. if this is true we should upgrade to v13 asap.
Thanks,
Hans
-
HansMeiser
- Enthusiast
- Posts: 92
- Liked: 14 times
- Joined: Jul 11, 2022 6:59 am
- Contact:
Re: Veeam 12 still Security Fixes?
Hello,
no other explicit answers to this topic?
This should be an eminent question to all v12 Users.
It is still unanswered: Will v12 get at least security-fixes? Linked Product LifeCycle says no.
Thanks,
Hans
no other explicit answers to this topic?
This should be an eminent question to all v12 Users.
It is still unanswered: Will v12 get at least security-fixes? Linked Product LifeCycle says no.
Thanks,
Hans
-
david.domask
- Veeam Software
- Posts: 3350
- Liked: 785 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Veeam 12 still Security Fixes?
Hi Hans,
As noted, our focus is always on the newest releases. Products still under support may receive additional patches / fixes on a case by case basis, however it is generally best to upgrade sooner than later.
As noted, our focus is always on the newest releases. Products still under support may receive additional patches / fixes on a case by case basis, however it is generally best to upgrade sooner than later.
David Domask | Product Management: Principal Analyst
-
kevin.boddy
- Service Provider
- Posts: 277
- Liked: 43 times
- Joined: Jan 30, 2018 3:24 pm
- Full Name: Kevin Boddy
- Contact:
Re: Veeam 12 still Security Fixes?
Hi,
We get told V12 fixes will be on case by case basis and to get upgraded to the current version as soon as time allows but when I bring up the fact that V13 has been a disaster for us with so many problems still not fixed, I am told why didn't you wait and stay on v12.
Which is it? Install broken V13 software or stay on working V12 but risk not getting any security fixes?
Thanks
Kevin
We get told V12 fixes will be on case by case basis and to get upgraded to the current version as soon as time allows but when I bring up the fact that V13 has been a disaster for us with so many problems still not fixed, I am told why didn't you wait and stay on v12.
Which is it? Install broken V13 software or stay on working V12 but risk not getting any security fixes?
Thanks
Kevin
-
ITP-Stan
- Expert
- Posts: 237
- Liked: 83 times
- Joined: Feb 18, 2013 10:45 am
- Full Name: Stan G
- Contact:
Re: Veeam 12 still Security Fixes?
We are still on V12 as well.
I tried V13 in my homelab personally and was disappointed by the load it generates.
It's become such a bloated piece of software, the system requirements are ludicrous.
And all the unused plugins & services are installed by default & running to use even more resources.
I tried V13 in my homelab personally and was disappointed by the load it generates.
It's become such a bloated piece of software, the system requirements are ludicrous.
And all the unused plugins & services are installed by default & running to use even more resources.
-
david.domask
- Veeam Software
- Posts: 3350
- Liked: 785 times
- Joined: Jun 28, 2016 12:12 pm
- Contact:
Re: Veeam 12 still Security Fixes?
Kevin, Stan,
I appreciate your points and am sorry to hear you had challenges on v13; for those items please do create cases and let Veeam Support review, and for feature requests / requests for change please create new topics so we can review the situation and keep this topic focused on the question from the topic creator.
Updating to the latest supported version is always our recommendation.
I appreciate your points and am sorry to hear you had challenges on v13; for those items please do create cases and let Veeam Support review, and for feature requests / requests for change please create new topics so we can review the situation and keep this topic focused on the question from the topic creator.
Updating to the latest supported version is always our recommendation.
David Domask | Product Management: Principal Analyst
-
kevin.boddy
- Service Provider
- Posts: 277
- Liked: 43 times
- Joined: Jan 30, 2018 3:24 pm
- Full Name: Kevin Boddy
- Contact:
Re: Veeam 12 still Security Fixes?
So basically.
No guaranteed fixes available for V12.
Install buggy V13 instead.
No guaranteed fixes available for V12.
Install buggy V13 instead.
-
JPMS
- Expert
- Posts: 153
- Liked: 74 times
- Joined: Nov 02, 2019 6:19 pm
- Contact:
Re: Veeam 12 still Security Fixes?
Veeam really need to get a grip on this sort of stuff. They seem to have lost all interest in what their customers need and what modern IT standards require.
There is already a significant discussion on the massive bloatware that Veeam is becoming here post541369.html. I only mention this because it is another example of how Veeam has lost touch with what IT professionals need.
Backup software is one of the critical parts of IT infrastructure. It is not something you rush to change when a vendor brings out a major new version with lots of changes. Does Veeam not understand that? Are your own internal IT practices so poor that you leap on every bit of shiny new stuff that's dangled in front of you as soon as it comes out?
You even make yourself look foolish - https://www.veeam.com/product-lifecycle.html. End of Fix for v12, September 2025, Release Date v13, November 2026! You're on your own for the gap between?!
I get that you want to move people on ASAP but it is rarely that simple for us. I can just about live with a 'no fixes' policy but it is essential that there is a guarantee of security fixes for a reasonable period of time. I would suggest six months, so upgrades can be properly planned, tested and implemented.
There is already a significant discussion on the massive bloatware that Veeam is becoming here post541369.html. I only mention this because it is another example of how Veeam has lost touch with what IT professionals need.
Backup software is one of the critical parts of IT infrastructure. It is not something you rush to change when a vendor brings out a major new version with lots of changes. Does Veeam not understand that? Are your own internal IT practices so poor that you leap on every bit of shiny new stuff that's dangled in front of you as soon as it comes out?
You even make yourself look foolish - https://www.veeam.com/product-lifecycle.html. End of Fix for v12, September 2025, Release Date v13, November 2026! You're on your own for the gap between?!
I get that you want to move people on ASAP but it is rarely that simple for us. I can just about live with a 'no fixes' policy but it is essential that there is a guarantee of security fixes for a reasonable period of time. I would suggest six months, so upgrades can be properly planned, tested and implemented.
-
HolgerE
- Influencer
- Posts: 12
- Liked: 2 times
- Joined: Mar 11, 2014 8:37 am
- Full Name: Holger Ernst
- Contact:
Re: Veeam 12 still Security Fixes?
Major version upgrades were no big deal the last 10 years.
But after upgrading our (quite small) environment from v12 to v13 shows one bug after another. We have the second private fix running, now we are able to backup VMs without abortions again (this fix is still not public). But we still have a lot of warnings.
So I also don't understand why Veeam pushes people to upgrade to an unstable v13.
Currently we (have to) advise all our customers to stay at v12.
But after upgrading our (quite small) environment from v12 to v13 shows one bug after another. We have the second private fix running, now we are able to backup VMs without abortions again (this fix is still not public). But we still have a lot of warnings.
So I also don't understand why Veeam pushes people to upgrade to an unstable v13.
Currently we (have to) advise all our customers to stay at v12.
-
HannesK
- Product Manager
- Posts: 15869
- Liked: 3543 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Veeam 12 still Security Fixes?
Hello,
agree, the lifecycle page looks not good and I will work internally on that.
The "end of fix" date exists "since always" and was initially created to avoid that customers expect hotfixes for regular bugs. In the past, we delivered also security fixes after "end of fix" and if needed, that would also happen to V12 for a certain amount of time.
Would a separate "end of security fix" column with X months on top of "end of fix" help?
Best regards
Hannes
agree, the lifecycle page looks not good and I will work internally on that.
The "end of fix" date exists "since always" and was initially created to avoid that customers expect hotfixes for regular bugs. In the past, we delivered also security fixes after "end of fix" and if needed, that would also happen to V12 for a certain amount of time.
Would a separate "end of security fix" column with X months on top of "end of fix" help?
Best regards
Hannes
-
JPMS
- Expert
- Posts: 153
- Liked: 74 times
- Joined: Nov 02, 2019 6:19 pm
- Contact:
Re: Veeam 12 still Security Fixes?
Hannes,
A basic security requirement for your customers is that you don't utilise software that no longer receives security fixes. If you are considering a product's EOL, that is the key date and we need to know when that is. It is not enough to say that you may make security fixes available "for a certain amount of time" after the 'end of fix' date because we don't know that you definitely will and we don't have a firm date until when.
So yes, a published date for security fixes, would make our lives a lot easier. We then have a definite date to plan around.
That isn't to say there isn't some risk about continuing to utilise software that is no longer receiving fixes but there is also a risk moving to a new version. It is something we have to balance all the time. Ideally, there would be a longer overlap between two versions, when both are fully supported. Some companies offer that, some, like yourselves, don't.
A basic security requirement for your customers is that you don't utilise software that no longer receives security fixes. If you are considering a product's EOL, that is the key date and we need to know when that is. It is not enough to say that you may make security fixes available "for a certain amount of time" after the 'end of fix' date because we don't know that you definitely will and we don't have a firm date until when.
So yes, a published date for security fixes, would make our lives a lot easier. We then have a definite date to plan around.
That isn't to say there isn't some risk about continuing to utilise software that is no longer receiving fixes but there is also a risk moving to a new version. It is something we have to balance all the time. Ideally, there would be a longer overlap between two versions, when both are fully supported. Some companies offer that, some, like yourselves, don't.
-
FCU_JE
- Enthusiast
- Posts: 40
- Liked: 14 times
- Joined: Oct 09, 2024 6:17 pm
- Contact:
Re: Veeam 12 still Security Fixes?
I asked this question quite a while ago. No answers. No updates to the policy.
veeam-backup-replication-f2/veeam-produ ... 00014.html
veeam-backup-replication-f2/veeam-produ ... 00014.html
-
HansMeiser
- Enthusiast
- Posts: 92
- Liked: 14 times
- Joined: Jul 11, 2022 6:59 am
- Contact:
Re: Veeam 12 still Security Fixes?
Hello,
thanks to all posters.
I think we were able to clarify our perspective as backup administrators to the software manufacturer.
We dont need fixes for programmfunctions after date x, but we need a clear stance and assurance regarding security updates. Typical this end with final end of support.
"may or may not...", "mostly" does not meet my expectations.
Thanks,
Hans
thanks to all posters.
I think we were able to clarify our perspective as backup administrators to the software manufacturer.
We dont need fixes for programmfunctions after date x, but we need a clear stance and assurance regarding security updates. Typical this end with final end of support.
"may or may not...", "mostly" does not meet my expectations.
Thanks,
Hans
-
HannesK
- Product Manager
- Posts: 15869
- Liked: 3543 times
- Joined: Sep 01, 2014 11:46 am
- Full Name: Hannes Kasparick
- Location: Austria
- Contact:
Re: Veeam 12 still Security Fixes?
Hello,
JPMS & HansMeiser: it's clear what is needed, thank you.
FCU_JE: thanks for that thread, I will add that to the conversation that I started earlier today.
Best regards
Hannes
JPMS & HansMeiser: it's clear what is needed, thank you.
FCU_JE: thanks for that thread, I will add that to the conversation that I started earlier today.
Best regards
Hannes
-
RubinCompServ
- Service Provider
- Posts: 420
- Liked: 134 times
- Joined: Mar 16, 2015 4:00 pm
- Full Name: David Rubin
- Contact:
Re: Veeam 12 still Security Fixes?
Not sure where you see a release date of anything of November 2026 (especially considering that v13 was released months ago already), but it seems obvious that it was a typo.
Who is online
Users browsing this forum: AdsBot [Google], Bing [Bot], jasonede and 266 guests