Security

Hybrid FIPS + Post-Quantum Cryptography (PQC) processing — With this release, Veeam Backup & Replication introduces a hybrid FIPS + PQC model that uses post-quantum algorithms (aligned with NIST FIPS 203, 204, and 205) for handshake and key exchange, while retaining FIPS-certified AES for data encryption. PQC support is enabled on existing deployments without requiring data migration or infrastructure changes. When strict FIPS compliance mode is enabled, PQC functionality is automatically disabled to ensure full adherence to FIPS requirements.

MFA enforcement for Users and Roles changes — Any change to Users and Roles settings now requires MFA confirmation (when enabled), adding a checkpoint to the most sensitive configuration area for your backup server.

Windows Event Log Integration for Security & Compliance — Security & Compliance Analyzer findings and status changes can now be published directly to the Windows Event Log. This enables integration with SIEM, Syslog, and other security monitoring platforms, allowing organizations to incorporate backup infrastructure compliance events into existing security operations and monitoring workflows.

SAML Backup server certificate — The SAML configuration page now uses the backup server certificate as the default Service Provider certificate, removing a manual selection step when configuring SAML single sign-on.

Exportable SAML certificate — Service Provider certificate can now be exported via the Download action in SAML configuration, simplifying IdP metadata exchange.

Encryption password change notifications — Changing backup encryption password now records a notification in the affected job’s session log and generates an event, providing an audit trail for key rotation.

Configurable Web UI port for Windows Deployments — With this release the software allows administrators to configure a custom port for web services instead predefined of 443 port during backup server deployment or modify it later as needed.

Single-port transport — Previously, backup communication relied on a wide dynamic port range (2500–3300), increasing firewall complexity and expanding the potential attack surface in segmented environments. With this release, all backup communication uses a single port, eliminating the need for dynamic port ranges. This capability simplifies firewall configuration, reduces the attack surface, and enables easier deployment in secure and segmented network environments.

REST API Port — The REST API no longer requires a dedicated port and answers on port 443. Port 9419 remains open for backward compatibility so existing scripts aren’t broken by this upgrade, and will be deprecated in a future release.

RBAC restore options refinement — Restore options for custom operator users now include grouping, descriptions, and search, making the right action easier to find.

.NET 10 adoption — The backup server components are migrated to .NET 10, delivering security patches, performance improvements, and continued long-term support alignment.