Monthly Release Notes - July 2026

Jump to:

 

Boldon James


CAD Classifier for AutoCAD

Version 3.16.1

July 3, 2026

Fixes
  • CAD Classifier for AutoCAD sometimes prevented users from classifying unclassified documents and closing AutoCAD. This issue has been resolved.

Classifier Mail Add-in

Version 3.14

July 14, 2026

New Features
  • Added support for displaying multiple languages in Classifier Mail Add-in dialogs. See the Classifier Administration Server User Guide for instructions.
  • Added support for help link. See the Classifier Administration Server User Guide for instructions.
  • Added a configurable registry key for the error message that customers see when an Exchange Web Services (EWS) request returns an access denied error. See the Classifier Mail Add-in Installation Guide for instructions.
  • Added support for including integrity check information in email X-headers.
Enhancements
  • Confirmed support for Windows Server 2025.
  • Confirmed support for Exchange Server Subscription Edition (SE).
  • Confirmed support for Windows Server Core 2022.

Back to Top

 

Clearswift


Secure Email Gateway

Version 6.3.1

July 7, 2026

NOTE:

Version 6.3.1 does not come with the following.

  • Product ISOs

  • Product documentation (Online Help and Installation Guides)

For Japanese Release Notes, click here.

Fixes
  • Restored the ability to use wildcards (*) when specifying hosts in the connection profile.

  • Improved PDF processing.

  • Improved detection of spoofed messages.

  • OCR enhancements reduced file processing time.

  • Improved logging to prevent erroneous entries.

  • Enforced stronger ciphers used in the product UI.

  • Ensured that the Message-ID header in auto-generated NDRs (Non Delivery Reports) is RFC compliant.

  • Resolved a UI layout issue when viewing Held Messages and Track Messages.

  • Resolved an issue where attachments downloaded from Held Messages on a remote peer would be corrupt.

  • Resolved an issue where the SMTP log was not displayed on a remote peer when using the Track Messages feature.

  • Resolved an issue where temporary files from failed scans were not being cleared up correctly and could fill up the space.

  • Resolved an issue where outbound messages sent from Microsoft 365 were rejected with BATV validation error due to improperly tagged recipients.

  • Resolved an issue where the audit service entered a loop of repeated failures.

  • Resolved an issue where the chronyd service was restarted every two minutes.

Secure Exchange Gateway

Version 6.3.1

July 7, 2026

NOTE:

Version 6.3.1 does not come with the following.

  • Product ISOs

  • Product documentation (Online Help and Installation Guides)

For Japanese Release Notes, click here.

Fixes
  • OCR enhancements reduced file processing time.

  • Improved logging to prevent erroneous entries.

  • Enforced stronger ciphers used in the product UI.

  • Resolved a UI layout issue when viewing Held Messages and Track Messages.

  • Resolved an issue where attachments downloaded from Held Messages on a remote peer would be corrupt.

  • Resolved an issue where the SMTP log was not displayed on a remote peer when using the Track Messages feature.

  • Resolved an issue where temporary files from failed scans were not being cleared up correctly and could fill up the space.

  • Resolved an issue where the chronyd service was restarted every two minutes.

Secure ICAP Gateway

Version 6.3.1

July 7, 2026

NOTE:

Version 6.3.1 does not come with the following.

  • Product ISOs

  • Product documentation (Online Help and Installation Guides)

For Japanese Release Notes, click here.

Fixes
  • OCR enhancements reduced file processing time.

  • Improved logging to prevent erroneous entries.

  • Enforced stronger ciphers used in the product UI.

  • Resolved an issue where the chronyd service was restarted every two minutes.

Secure Web Gateway

Version 6.3.1

July 7, 2026

NOTE:

Version 6.3.1 does not come with the following.

  • Product ISOs

  • Product documentation (Online Help and Installation Guides)

For Japanese Release Notes, click here.

Fixes
  • OCR enhancements reduced file processing time.

  • Improved logging to prevent erroneous entries.

  • Enforced stronger ciphers used in the product UI.

  • Resolved an issue where the chronyd service was restarted every two minutes.

Back to Top

 

Digital Guardian


Agent for Windows

Version: 11.1.1

July, 2026

New Features
  • The Windows Agent now enhances ADE event reporting in DGMC and ARC by including parent and grandparent process information for improved visibility into the application that generated the event for applications such as New Microsoft Outlook and New Teams. This enhancement helps improve visibility in scenarios where events generated from olk.exe are reported in DGMC LFR as msedgewebview2.exe.

  • Improved ACI timeout handling so that when no timeout is explicitly configured, the agent automatically calculates an appropriate inspection timeout using the built-in heuristic.

Fixes
  • Resolved an issue where the application would hang when using ADE Paste due to unresponsive interprocess communication (IPC) channels.

  • Resolved an issue where process flags were not applied consistently to applications launched from network share paths, while the same applications launched from local file system paths were processed correctly.

  • Resolved an issue where older Digital Guardian Windows agent versions applied incorrect process flags to kvoop.exe when using the 11.1 process flag file, potentially affecting classification functionality.

  • Resolved an issue where applications would hang when ACI was enabled due to a DGAdmin crash caused by incomplete initialization.

  • Resolved an issue that could lead to unexpected application failures during file copy operations, including when files are copied by dragging and dropping them in Explorer by adding safeguards around the affected code path.

  • Resolved an issue where initialization timing during user logon could cause applications, such as Windows Explorer, to crash during application startup and potentially affect system stability.

  • Resolved an issue on Windows 26H1 where the Windows toolbar search functionality did not work correctly when the DG Agent was installed.

  • Resolved an issue where content inspection processed Outlook mailbox cache files (*.ost, *.ost.tmp, *.pst, and *.pst.tmp) during DG MIP integrated feature operations. Refer to the Digital Guardian Agent for Windows 11.1.1 Release Notes > Resource File Changes section for additional details.

  • Resolved an issue where enabling the aciLogEntityScores custom configuration could log sensitive matched content in ACI debug logs.

  • Resolved issues related to proxy PAC configuration handling and duplicate PAC fetch error logging in the Windows Agent.

  • Resolved an issue where Outlook attachments with URL encoded file paths were not processed correctly during analysis.

  • Resolved an issue where a timing conflict during agent shutdown could result in a system blue screen (BSOD) from the Microsoft WFP stack.

  • Resolved issues that caused logging crashes.

  • Resolved an issue where the HKEY_CURRENT_USER\SOFTWARE\Classes registry key was not visible when Stealth mode was enabled. This update adds support to correctly follow registry links to ensure the key and its subkeys is visible as expected.

  • Resolved an issue where newer NtQuerySystemInformation classes on Windows 11 25H2 could expose hidden DG processes while stealth mode was enabled.

  • Resolved an issue that caused verification of Microsoft (MSFT) co-signed agent binaries to fail.

  • Resolved an issue where the DG MSI installer displayed legacy Verdasys contact information instead of Digital Guardian/Fortra details in MSI metadata.

  • Resolved an issue where repeated heartbeat timeout restarts could prevent long-running DGAgent.exe operations from completing successfully.

For additional details on resource file changes, refer to the Digital Guardian Agent for Windows 11.1.1 Release Notes under the Resource File Changes section on Fortra Support Portal.

Agent for Linux

Version: 12.2.3

July 2026

Updates
  • The Linux Agent RPM Package is Now Native and GPG-Signed

    The Linux agent continues to support both the standard installer and RPM-based installation. Starting with this release, the RPM package is a native RPM and is signed with a trusted GPG key. With the native RPM package, installed files are declared and managed by the RPM database. You can also verify the package’s authenticity and integrity by using the GPG signature. Use either the standard installer or the RPM package, depending on your deployment requirements.

  • Certification for Additional Kernels

    This table lists the additional certified Linux kernels for Red Hat Enterprise Linux (RHEL) and Ubuntu in this release. Refer to the Agent for Linux User's Guide for details about the packages required to support the new kernel versions for the Agent. Refer to Agent_for_Linux_v12.x.x_and_later_RHEL_Certified_Environments and Agent_for_Linux_v12.x.x_and_later_Ubuntu_Certified_Environments for the complete lists of supported RHEL and Ubuntu kernels.

    Distribution

    Version

    Architecture

    Kernel

    RHEL

    10.1

    64-Bit kernel-6.12.0-124.56.1.el10_1
    RHEL 10.1 64-Bit kernel-6.12.0-124.55.1.el10_1
    RHEL

    10.0

    64-Bit kernel-6.12.0-55.77.1.el10_0
    RHEL 10.0 64-Bit kernel-6.12.0-55.76.1.el10_0
    RHEL 10.0 64-Bit kernel-6.12.0-55.75.1.el10_0
    RHEL 10.0 64-Bit kernel-6.12.0-55.73.1.el10_0
    RHEL 10.0 64-Bit kernel-6.12.0-55.72.1.el10_0
    RHEL 10.0 64-Bit kernel-6.12.0-55.71.1.el10_0
    RHEL 9.7 64-Bit kernel-5.14.0-611.55.1.el9_7
    RHEL 9.7 64-Bit kernel-5.14.0-611.54.1.el9_7
    RHEL 9.6 64-Bit kernel-5.14.0-570.120.1.el9_6
    RHEL 9.6 64-Bit kernel-5.14.0-570.119.1.el9_6
    RHEL 9.6 64-Bit kernel-5.14.0-570.116.1.el9_6
    RHEL 9.6 64-Bit kernel-5.14.0-570.114.1.el9_6
    RHEL 9.6 64-Bit kernel-5.14.0-570.113.1.el9_6
    RHEL 9.6 64-Bit kernel-5.14.0-570.112.1.el9_6
    RHEL 9.4 64-Bit kernel-5.14.0-427.127.1.el9_4
    RHEL 9.4 64-Bit kernel-5.14.0-427.126.1.el9_4
    RHEL 9.4 64-Bit kernel-5.14.0-427.125.1.el9_4
    RHEL 9.4 64-Bit kernel-5.14.0-427.124.1.el9_4
    RHEL 8.10 64-Bit kernel-4.18.0-553.132.1.el8_10
    RHEL 8.10 64-Bit kernel-4.18.0-553.129.1.el8_10
    RHEL 8.10 64-Bit kernel-4.18.0-553.126.1.el8_10
    RHEL 8.10 64-Bit kernel-4.18.0-553.125.1.el8_10
    RHEL 8.10 64-Bit kernel-4.18.0-553.124.1.el8_10
    RHEL 8.10 64-Bit kernel-4.18.0-553.123.1.el8_10
    Ubuntu 24.04 64-Bit linux-image-6.17.0-35-generic
    Ubuntu 24.04 64-Bit linux-image-6.17.0-29-generic
    Ubuntu 24.04 64-Bit linux-image-6.17.0-23-generic
    Ubuntu 24.04 64-Bit linux-image-6.17.0-22-generic
    Ubuntu 24.04 64-Bit linux-image-6.8.0-124-generic
    Ubuntu 24.04 64-Bit linux-image-6.8.0-117-generic
    Ubuntu 24.04 64-Bit linux-image-6.8.0-111-generic
    Ubuntu 22.04 64-Bit linux-image-6.8.0-124-generic
    Ubuntu 22.04 64-Bit linux-image-6.8.0-111-generic
    Ubuntu 22.04 64-Bit linux-image-6.8.0-110-generic
    Ubuntu 22.04 64-Bit linux-image-5.15.0-181-generic
    Ubuntu 22.04 64-Bit linux-image-5.15.0-179-generic
    Ubuntu 22.04 64-Bit linux-image-5.15.0-177-generic
Fixes
  • No fixes in this release.

Back to Top

 

Globalscape


EFT Health Check Agent

Version 1.9.9

July 23, 2026

  • Fixed false-positive detections in event rules configured with connection profiles.

  • Corrected hostname scanning behavior for conditions containing multiple hostnames.

  • Enhanced the user interface and overall user experience.

  • Optimized memory usage to improve performance and stability.

EFT Reporting Plus

Version 2.1.1.0

July 15, 2026

  • Added support for EFT 8.3.4.

  • Added Group Membership Report.

  • Added support for paths in all actions to the EFT Event Rule Dependency Report.

Version 2.1.0.0

July 8, 2026

  • Added EFT Configuration reports.

    • EFT User Report for key user account fields.

    • EFT User Full Report with counters, lock state, password age, last login, and home-folder permission detail.

    • EFT Connection Profiles Report with event-rule usage counts.

    • EFT Advanced Workflow Report with event-rule usage counts.

    • EFT Event Rules Dependencies Report for referenced resources and automation dependencies.

    • EFT Event Rules Complexity Report for condition, statement, and action-count metrics.

  • Added Event Rule History view for last execution status and success rate.

    • Drill-in view for execution actions and action details.

    • Failure-focused filtering for faster troubleshooting.

    • Transaction-aware action tracing to understand related activity.

    • Human-readable action summaries for common EFT action types.

  • Add support to Run EFT ARM reports directly from Reporting Plus without using EFT reporting engine. Server-side validation, parameter binding, paging, sorting, and CSV export.

  • Add size of DB stats.

  • Added EFT Event Rules.

EFT

Version 8.3.4

July 7, 2026

New Features

ARM

  • Added support for ARM reports for cloud locations.

Cloud Connectors

  • Support for SharePoint in Connection Profiles.

  • Support for SharePoint in Monitor Folder (cloud).

  • Support for SharePoint in VFS.

  • Support for Entra ID authentication for Azure Cloud in Connection Profiles.

Web Admin Client (WAC)

  • Added support to refresh the user database.

  • Added support to view licensing status and registration details.

  • Added ability to refresh user database for AD and LDAP configured sites.

Enhancements

Administration

  • Updated Threat Brain URLs.

Automate Workflow Module (AWM)

  • Improved task execution performance and timeout handling, especially when many run-task requests occur in short succession.

  • Updated AWE to the new AWE Agent 26, including installer, service, API, branding, and endpoint work.

  • Removed the Automate Task Administrator.

  • Improved EFT memory usage when executing Event Rules asynchronously with AWE tasks.

  • Updated the SSH library used in AWE.

Cloud Connectors

  • Support for Google Drive shared drives.

  • Updated the Azure SDK to version 12.17.0.

  • Updated the Google Drive SDK to version 1.74.0.

Installer

  • Updated installer binaries related to build signing, MSI signing, and prior-install resolution.

  • Updated log4net to version 3.3.1.0.

  • Updated Newtonsoft.Json for Outlook add-in to version 13.0.4.

  • Enabled Control Flow Guard (CFG) on EFT binaries.

Logging

  • Updated the GetAddrInfoW logger from Debug to Error.

REST API

  • Updated licensing REST API to include additional details.

  • Updated REST API support to determine all licensed modules and serial numbers.

Web Admin (WAC)

  • Updated various translations in our Web Admin Client portal.

  • Removed the Axios library from Web Admin.

  • Added route guards to redirect users away from routes they cannot access.

  • Added Globalscape Help and KB article links in the Web Admin portal.

Web Transfer Client (WTC)

  • Accessibility improvements for WTC continue, including support work for WCAG 2.2 AA / ADA Title 2 requirements.

  • Updated Angular to version 21.x.

Fixes

ARM

  • Fixed upgrade blockers including database upgrade failures from 8.3.2.

  • Fixed crashes involving ODBC sites on startup.

  • Fixed an issue where the EFT database would record a successful archive step as a failure.

  • Fixed an issue where a PGP Event Rule action failure would not properly write the failure to the database.

Automate Workflow Module (AWM)

  • Fixed an issue where AWE arrays could fail after upgrading to Automate Desktop v2024 or v2025.

  • Fixed an issue where Task variables were not passed from AWE to Event Rules in EFT 8.3.

  • Fixed an issue where AWE logs would report a "12002 The operation timed out" error.

  • Fixed an issue where AML files were being generated in the C:\Windows\Temp directory.

  • Fixed an issue where AWE would error when reading a file to a variable.

  • Fixed an issue where the upgraded AML task version in the EFT site's SQLite file would not reference the correct version.

  • Fixed an issue where the Automate Service account was stored in plaintext in the serverconfig.db.

  • Fixed an issue where the name of the workflow in the title bar would change when edited in the AWE Task builder.

  • Fixed an issue where AWE workflows that failed due to limit rejections were not properly logged in the EFT logger.

Cloud Connector

  • Fixed an issue where large file uploads to cloud endpoints such as Google, AWS S3, and Azure would fail.

  • Resolved multipart upload corruption and chunk ordering issues for S3 and Google Cloud Storage.

  • Fixed an issue where Azure Blob uploads larger than 5 GB would fail.

  • Resolved Azure Data Lake Gen2 connection failures that could crash the EFT service.

EFT Administration

  • Corrected TLS/FIPS-related inconsistencies and UI display issues for cipher configuration.

  • Fixed invalid SSL certificate behavior after upgrade in some HTTP scenarios.

  • Addressed HA node crash behavior when used with HA Proxy in round robin mode.

  • Fixed an issue where EFT Administration would fail to connect after a trial had expired when configured on a non-standard port.

Event Rules

  • Fixed an issue where EFT could crash when moving Event Rule conditions.

  • Fixed an issue where the condition "If using Remote Agent" would not work as expected.

  • Fixed an issue where under certain configurations the OpenPGP action would fail to encrypt the file.

FTP Protocol

  • Fixed an issue where CuteFTP multi-part upload to EFT would fail to be rebuilt after completion.

Installer

  • Fixed an issue where, during upgrades, prior OLE DB Drivers for SQL were not removed.

  • Updated the EFT uninstaller to remove AWE when EFT is uninstalled.

REST API

  • Resolved cases where REST endpoints returned missing fields, incorrect status codes, incorrect payload formats, or 500 errors for invalid input.

  • Corrected site naming validation, SMS endpoint validation, and multiple endpoint schema inconsistencies.

  • Improved visibility of registration and licensing data in Web Admin and REST API flows.

  • Removed camel-cased endpoints.

  • Fixed an issue where, under certain conditions, EFT could crash when sending an improperly configured REST API call for virtual folder creation.

Outlook Add-in

  • Updated the Outlook add-in to the correct version. The previous 8.3.2 release included an older add-in version.

EFT Propagation

  • Fixed an issue where Site Propagate would fail to transfer site templates.

SFTP (SSH)

  • Fixed an issue where EFT's log would report an SFTP connection error with a "-1: bad id" message.

Web Admin Client

  • Fixed Web Admin issues affecting user editing, notifications, user refresh behavior, and translation quality.

Workspaces

  • Fixed an issue where Workspace Send requests did not adhere to the expected body format.

  • Fixed an issue that would cause Workspace email verification links to fail if the owner username contained special characters.

WTC

  • Fixed an issue where setting Max Transfer speeds to a low value would cause WTC to render improperly.

Known Issues

AWE

  • Under high load environments AWE Agent 26 could report Windows Event Viewer errors.

  • Selecting the Send options under AWE File Menu causes AWE to crash.

  • AWE does not send emails when EFT is configured with Gmail Oath.

  • AWE workflows may fail to connect to hmac-sha2-256/512-etm@openssh.com clients.

Connection Profiles

  • In some cases, changing the certificate in an Entra ID-configured Connection Profile does not display the Apply button.

Workspaces

  • Workspaces Send fails when EFT's site root is configured in AWS cloud.

Back to Top

 

GoAnywhere


GoAnywhere MFT

Version: 7.10.1

July 23, 2026

Enhancements
  • Added a Lucene Directory Type flag for Auto, NIO, or MMAP indexing behavior, including upgrade migration from the previous system property and improved Windows UNC path startup support.
  • Added a new V2 RADIUS provider that supports Message Authenticator.
  • Added opt-in Agent Transfer thread caching to increase performance.
  • Added the ability to enable transfer thread pooling for Agent transfers.
  • Enhanced Login Settings 2FA Radius to select V1/V2 provider and optionally specify 'Require Message Authenticator'.
  • Enhanced RADIUS Login Methods to select V1/V2 provider and optionally specify 'Require Message Authenticator'.
  • Enhanced the application to provide a trust manager that can be accessed by database JDBC drivers that provides the live host values from the connection.
  • Enhanced upgrades to continue when older database indexes are already missing.
  • Fixed Lucene lock implementation to use a simple lock by default for wide adoption. Opt-Out is available via Flag
  • GoAnywhere MFT has successfully renewed its Drummond Certification.
Fixes
  • Both Job File Audit IDs and Job IDs are now generated using a new approach that ensures every id is unique, eliminating the possibility of duplicate ids without requiring database or cluster resources. As part of this change, id values will be much larger than before. This is expected, and the order in which IDs are created is still maintained.
  • Added a flag to Attack Monitors to provide a regular expression used to configure the allowed hosts to resolve if one is encountered determining if IP is local.
  • Added an advanced Agents flag that allows admins to adjust the time in seconds to wait for a reply from the agent.
  • Added an advanced Agents flag that toggles the cleanup logic for expired items in the transfer cache.
  • Added an advanced flag allowing to control the amount of time to wait for jobs to finish during a shutdown.
  • Fixed a race condition that can occur canceling active jobs on shutdown vs coordinator canceling the same jobs.
  • Fixed Agents download back pressure timeout to be adjustable via Flag and no longer used for idle verification.
  • Fixed Agents transfer idle verification to use keep alive process.
  • Fixed an issue when editing a web user or web user group where the virtual folder tree structure would not retain its expanded or collapsed state
  • Fixed an issue when using Agent file syntax could cause a hung job.
  • Fixed an issue where Admin User password expiration emails could fail when the Admin Site URL was not configured.
  • Fixed an issue where authorized users could not import SSH Keys into the System Key Vault by using GACMD or legacy REST.
  • Fixed an issue where Execute SSH Command Task using Mina SSH Provider would timeout immediately when command timeout is set to indefinite(0).
  • Fixed an issue where queued transfer requests would cause a memory leak and held job when the response from the agent never occurs.
  • Fixed an issue where RPM upgrades could restore legacy HelpSystems userdata into the Fortra install on subsequent upgrades.
  • Fixed an issue where SFTP Upload Tasks using the Mina SSH Provider did not preserve the source file timestamp on uploaded files.
  • Fixed an issue with Active Transfers only showing local node transfers in a cluster.
  • Fixed an upgrader issue where Lucene index backup could fail when the configured index directory used a UNC/network share without proper upgrader account permissions.
  • Fixed Attack Monitors local IP validation to be more efficient by only doing DNS resolution if we encounter a hostname.
  • Fixed Null Pointer Error when running an interactive job logged in using SAML.
  • Fixed RPM installation on Amazon Linux 2023 and other supported Linux distributions by allowing compatible Java 11 runtime providers.
  • Improved security controls for Web Client pages and REST APIs.
  • Resolved an issue where SFTP connections using the Mina SSH client could fail during authentication when connecting through a forward proxy.
  • Updated Agent and Agent Template initial values for auto resume interval(30) and attempts(3) upon creation.
  • Updated Disk Quota processing to compress and batch quota adjustments when in a cluster
Updated Item
  • Updated Apache Tomcat 9.0.117 to 9.0.120
  • Updated JNQ from 2.7.1 to 2.7.4
  • Upgraded Netty from 4.2.12.Final to 4.2.15.Final
  • Upgraded the PostgreSQL JDBC driver to 42.7.11 in gamft-upgrader, updated tracked snapshot manifests to remove postgresql-42.7.3.jar, and verified database connectivity with a PostgreSQL smoke test.

GoAnywhere Agents

Version: 3.5.0

July 23, 2026

Enhancements
  • Improved application security and strengthen trust by digitally signing the executables using a trusted code-signing certificate.
  • Optimized client and server connection bridges during reverse and forward proxying to improve data transfer efficiency. Previously Opt-In and now enabled by default.
Fixes
  • Turn off BC native support to avoid permission issue on Unix systems.

Updated Item
  • Implemented a fix for UDP back pressure within Gateway. Packet loss experienced through UDP should be considerably lower.
  • Updated Azul Java 11 OpenJDK JRE 11.0.20 to 11.0.31.
  • Upgrade log4j-2.24.3 to log4j-2.25.4
  • Upgraded Netty from 4.2.12.Final to 4.2.15.Final.

GoAnywhere Gateway

Version: 2.6.1

July 23, 2026

Enhancements
  • Improved threading model for Agent transfers to improve transfer setup times.
Fixes
  • Fixed Agents transfer idle verification to use keep alive process.
  • Fixed Agents upload back pressure timeout to be adjustable via Flag and no longer used for idle verification.
  • Upgraded the PostgreSQL JDBC driver to 42.7.11 and added a PostgreSQL smoke test to verify connectivity and authentication continue to work.
Updated Item
  • Updated JNQ from 2.7.1 to 2.7.4
  • Upgraded Netty from 4.2.12.Final to 4.2.15.Final
Fixed Item
  • Fixed an issue where Execute SSH Command Task using Mina SSH Provider would timeout immediately when command timeout is set to indefinite(0).
  • Fixed an issue where SFTP Upload Tasks using the Mina SSH Provider did not preserve the source file timestamp on uploaded files.
  • Resolved an issue where SFTP connections using the Mina SSH client could fail during authentication when connecting through a proxy.

Outlook Plugin

Version 3.3.1

July 20, 2026

  • Updated log4net nuget package from version 2.0.15 to 3.3.2 (CVE-2026-40021)

Back to Top

 

Power Hub


Version 1.6

July 14, 2026

New Features
  • Fortra Application Hub is now Power Hub! Product has been rebranded.

  • Added support for installation on IBM i.

Fixes
  • Improved PostgreSQL upgrade script to detect modifications to UMASK.

  • Updated PostgreSQL to version 17.10 on Windows and Linux.

Known Issues
  • A warning message “Uninstalling will permanently delete all database data and cannot be undone. Click Cancel to exit and back up your data before continuing.“ will be displayed when upgrading the Windows version of Fortra Application Hub 1.5. This message only applies to full product uninstallations and not upgrades and can be disregarded. This has been resolved for future releases.

  • IBM i commands to start and end Power Hub are PHSTRHUB and PHENDHUB. They are incorrectly stated in the user guide.

Back to Top

 

Powertech


BoKS Manager

Version 9.0

July 28, 2026

Server s-9.0.0.6
NOTE:

This package requires that BoKS client package c-9.0.0.6 is also installed on the Master or Replica. If downgrading, note that both the server and client packages must be downgraded simultaneously using one and the same command.

Features
  • Added support for Microsoft Entra ID.

Fixes
  • Hostgroup-based access rules can fail for long hostgroup and hostname combinations.

  • Password history recording broken for new users/principals.

  • lsbks -VF can list users not blocked by too many login failures.

  • db_check.pl reported errors when checking password history after upgrading to BoKS 9.0.

  • boksuser -l displayed incorrect text for users blocked by too many login failures.

  • lsbks -D can show empty or incorrect password hash values.

  • lsbks -v displayed an incorrect message for expired passwords.

  • The ALLOW_REMOVE flag did not work for TYPE pre-registration entries.

  • Database upgrade left yescrypt password hash empty.

  • Sped up adding host to a Host Group (requires BoKS client package c-9.0.0.6 or later and BoKS server package s-9.0.0.6 or later).

Version 9.0

July 28, 2026

Client c-9.0.0.6
NOTE:

If you are installing this package on the Master or Replica, BoKS server package s-9.0.0.6 must also be installed on the Master or Replica.

New Features
  • Added support for Microsoft Entra ID.

Fixes
  • boksinfo hangs if the BoKS database is locked.

  • Allow 3-digit file modes for config vars.

  • Hostgroup-based access rules can fail for long hostgroup and hostname combinations.

  • BoKS does not start after upgrading to 9.0.

  • Speed up adding host to a Host Group (requires BoKS client package c-9.0.0.6 or later and BoKS server package s-9.0.0.6 or later).

  • Sudo and Suexec errors need to be more descriptive.

  • Missing fields in dictionary file.

Version 10.1

July 1, 2026

SSH Package boks-ssh-10.1.1.0
Updates
  • Rebased on OpenSSH 10.1.

  • Removed support for upgrading legacy tar installs.

Fixes
  • boks_sshd could ignore single-value MaxStartups configuration.

  • Unexpected setuid/setgid permission running BoKS Scp client. (CVE-2026-35385)

  • Command execution can occur via shell metacharacters. (CVE-2026-35386)

  • Unintended ECDSA algorithm acceptance. (CVE-2026-35387)

  • Missing multiplexing validation. (CVE-2026-35388)

Back to Top

 

Secure Collaboration (Vera)


Version 3.25.4

July 2026

Updates
  • Updated the Embedded Browser to Microsoft Edge — Windows Client

    • The Secure Collaboration (Vera) Windows client now uses Microsoft Edge as its embedded browser instead of Internet Explorer 11, which is no longer supported. This update improves security, enhances support for modern web standards, and provides a more reliable in-app browsing experience.

  • Added Support for Save As with Advanced Access Control — Mac Client

    • Support for Save As is now available for files protected by Advanced Access Control. When a protected file is saved to a new location, the client creates a secured copy at the destination and displays a confirmation. The saved copy can then be opened separately.

Fixes
  • Vera SaaS

    • Fixed an issue where users logging in via SAML could, in certain cases, see all available policies when encrypting files instead of only those assigned to their groups. This has been resolved. Users without any assigned policies now correctly see an empty policy list.

    • Fixed an issue where users signing in with external accounts (such as Gmail) couldn’t open Vera-protected files directly from SharePoint using the SPFx extension. Users saw a "Failed to open VERA" error even when they had access to both the file and the SharePoint site. This has been resolved. External users can now open Vera-protected files directly from SharePoint using Open with Vera.

    • Updated the Apache POI library from version 4.1.1 to 5.5.1 to fix an improper input validation vulnerability in versions earlier than 5.4.0. This update applies to the Vera Connectors in both on-premises and cloud deployments.

    • Fixed an issue where watermarked files could close unexpectedly when resizing the browser window or changing zoom. These actions were incorrectly detected as watermark tampering. This has been resolved, and normal browser actions no longer close files. Tamper detection continues to work for actual tampering.

      NOTE: Admins can now use Bypass watermark tamper enforcement in Settings > Privacy & Security > Security to exclude specific users, groups, or domains from enforcement. The watermark remains visible, but users aren’t removed if tampering is detected. If no scope is set, the bypass applies to all users. Audit events are still logged for visibility.
    • Fixed an issue where granting co-owner access to a group via SDK using only a group name or UUID-style resource name returned an internal error. This has been resolved. Co-owner access validation now correctly resolves groups by name or UUID, and co-owners can no longer accidentally downgrade an existing co-owner group's access level.

Back to Top

 

Security Awareness Training

Version: 1.129

July 23, 2026

Enhancements
  • Recurring reminder emails are now automatically deactivated when a course goes offline or is archived, preventing unnecessary scheduled emails.

  • Emails associated with a deleted course are now automatically removed from the Email Center.

  • The navigation experience has been improved so users can return directly to the course or quiz page from Send Email To and Email Summary pages. Previously, these actions returned users to the Email Center, requiring additional navigation steps.

Fixes
  • When filter lists contained more than 1,000 values, some valid search results were not returned, preventing users from selecting some filter values. This issue has been fixed, and matching values are now correctly displayed when searching within large filter lists.

  • When resizing the browser window, some buttons and page elements could become misaligned or partially displayed. This issue has been fixed.

  • Partner users encountered an error when opening the Notifications panel in French (FR-CA & FR-FR) and Spanish (ES-LATM). This issue has been fixed.

  • The Croatian date tag displayed dates in the U.S. format (MM/DD/YYYY) instead of the expected Croatian format (DD/MM/YYYY). This issue has been fixed.

  • Adding content from the catalog to the library could result in an error that prevented content from being added. This issue has been fixed.

  • Blocked phishing domains appeared available because they were no longer greyed out. This issue has been fixed to better indicate unavailable domains.

  • Phishing links were generated using HTTPS even when the selected domain did not support HTTPS and the HTTPS setting was not enabled. This issue has been fixed, and links now use HTTP unless HTTPS is explicitly enabled.

  • Opened PDF attachments were not counted in the Total Actions Performed chart on the Global Dashboard, causing reporting discrepancies. This issue has been fixed.

  • The Manager Username column prevented New User Uploads and User List Updates from completing, blocking uploads and updates. This issue has been fixed, and uploads now process correctly when the Manager Username column is included.

Version: 1.128.2

July 14, 2026

Enhancements
  • Enhanced Learning Zone performance and efficiency to improve scalability and support a better user experience during periods of high platform activity.

  • Administrators now receive a warning message when sending or scheduling course and quiz related emails for offline content, helping prevent emails from being sent for courses or quizzes that are unavailable.

  • Tooltip text has been updated for the course status option - Not Started/In Progress/Passed/Failed.

Fixes
  • The Operating System widget and Platform OS report displayed Windows 11 devices as Windows 10, making it difficult to accurately identify operating system versions. This issue has been fixed by updating the label to Windows 10/11, ensuring operating system data is displayed consistently across dashboards and reports.

  • Custom filter tags containing dashes did not resolve correctly in phishing simulation emails, landing pages, and feedback pages, preventing personalized values from being displayed. This issue has been fixed, and custom filter tags with dashes now render as expected.

  • A scheduled email did not reach all intended recipients, resulting in fewer emails being sent than expected. This issue has been fixed to ensure scheduled emails are delivered to all eligible recipients.

  • The Manager Email field was incorrectly labelled as Manager Username in user import and export files. This issue has been fixed, and the correct field name is now displayed.

  • Deleted phishing simulations continued to appear in the Phishing Simulations Events Log report even though they were no longer accessible, resulting in inaccurate reporting. This issue has been fixed, and deleted simulations are now excluded from the report.

  • Anonymous simulations displayed some identifiable user information in reports. This issue has been fixed to ensure report data remains anonymous.

  • The email template editor did not load for some environments, preventing administrators from updating email templates. This issue has been fixed, and templates can now be edited as expected.

  • Saving a phishing template without a reference name could make the My Saved Templates section unavailable. This issue has been fixed to ensure saved templates load correctly.

  • Course and quiz related emails were not sent when the associated content was offline, with no indication of why the emails were not delivered. This issue has been fixed by providing a clear warning message before the action is completed.


Version: 1.128.1

July 02, 2026

Fixes
  • Multiple bug fixes.

Back to Top