Monthly Release Notes - August 2026
Automate
Version 26.1.0
August 12, 2026
- Before installing Automate 26.1.0, confirm your version of Microsoft Windows is compatible with .NET Framework 4.8 and .NET 8.0.
- Before installing Automate Desktop 26.1.0, confirm your version of Microsoft Windows is compatible with .NET Framework 4.8. See .NET Framework System Requirements for more information.
-
As of version 11.7.1, Automate is only available as a 64-bit installer. However, agents can still be installed on both 32-bit and 64-bit platforms.
New Features
-
Added Multi-Factor Authentication (MFA) support to the Management Console.
Enhancements
-
Added the ability to configure SFTP logging levels and expanded logging to help diagnose connection failures.
-
Updated the SFTP versions drop-down to support selecting multiple versions.
-
Updated the SFTP engine used by FTP actions and added support for newer public-key, HMAC, and key-exchange algorithms.
-
Added MS Graph support for Email actions and activities, replacing Exchange Web Services (EWS) Online-based connections.
-
Added MS Graph support for sending task and workflow error-notification emails.
Fixes
-
Resolved an issue where the Agent appeared connected in the Management Console while its Windows system tray icon displayed Trying to connect.
-
Added safeguards against XML external entity (XXE) injection when reading AML files.
-
Resolved an AMExecute error caused by an incorrect Serilog configuration binding redirect.
Digital Guardian
Agent for Linux
Version: 14.0.0
August 2026
New Features
-
Added Support for Ubuntu 26
The DG Agent for Linux now supports Ubuntu 26.04 LTS with the 14.0.0 release.
-
SMTP Inspection Through the Web Inspection Proxy
Agent for Linux 14.0 now supports inspection and policy enforcement for outbound SMTP traffic through the existing Web Inspection Proxy (WIP). The Agent transparently redirects configured outbound SMTP connections to the shared WIP listener, so you do not need to install a separate SMTP proxy service or configure mail clients to use an explicit proxy.
WIP generates blockable Send Mail events and evaluates message metadata, message content, and correlated attachments against Digital Guardian policies. Messages that are allowed by policy are forwarded to the original SMTP server.
SMTP inspection is enabled by default for ports 25, 587, 465, and 2525. It supports plain SMTP, STARTTLS, implicit TLS on port 465, and the PLAIN, LOGIN, and XOAUTH2 authentication mechanisms over TLS.
-
Certification for Additional Kernels
This table lists the additional certified Linux kernels for Red Hat Enterprise Linux (RHEL) and Ubuntu in this release. Refer to the Agent for Linux User's Guide for details about the packages required to support the new kernel versions for the Agent. Refer to Agent_for_Linux_v14.x.x_and_later_RHEL_Certified_Environments and Agent_for_Linux_v14.x.x_and_later_Ubuntu_Certified_Environments for the complete lists of supported RHEL and Ubuntu kernels.
Distribution Version Architecture Kernel RHEL 10.2 64-Bit kernel-6.12.0-211.39.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.38.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.37.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.34.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.33.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.32.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.31.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.30.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.29.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.28.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.26.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.22.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.20.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.18.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.16.1.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.7.3.el10_2 RHEL 10.2 64-Bit kernel-6.12.0-211.7.1.el10_2 RHEL 10.0 64-Bit kernel-6.12.0-55.92.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.89.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.88.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.86.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.84.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.82.1.el10_0 RHEL 10.0 64-Bit kernel-6.12.0-55.79.1.el10_0 RHEL 9.8 64-Bit kernel-5.14.0-687.30.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.29.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.26.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.25.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.24.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.23.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.22.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.20.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.19.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.17.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.15.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.13.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.12.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.10.1.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.5.3.el9_8 RHEL 9.8 64-Bit kernel-5.14.0-687.5.1.el9_8 RHEL 9.6 64-Bit kernel-5.14.0-570.129.1.el9_6 RHEL 9.6 64-Bit kernel-5.14.0-570.128.1.el9_6 RHEL 9.6 64-Bit kernel-5.14.0-570.127.1.el9_6 RHEL 9.6 64-Bit kernel-5.14.0-570.125.1.el9_6 RHEL 9.6 64-Bit kernel-5.14.0-570.123.1.el9_6 RHEL 8.10 64-Bit kernel-4.18.0-553.147.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.146.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.144.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.143.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.141.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.140.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.139.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.137.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.136.1.el8_10 RHEL 8.10 64-Bit kernel-4.18.0-553.134.1.el8_10 Ubuntu 26.04 64-Bit linux-image-7.0.0-28-generic Ubuntu 26.04 64-Bit linux-image-7.0.0-27-generic Ubuntu 26.04 64-Bit linux-image-7.0.0-22-generic Ubuntu 26.04 64-Bit linux-image-7.0.0-14-generic Ubuntu 24.04 64-Bit linux-image-7.0.0-28-generic Ubuntu 24.04 64-Bit linux-image-6.17.0-40-generic Ubuntu 24.04 64-Bit linux-image-6.8.0-136-generic Ubuntu 24.04 64-Bit linux-image-6.8.0-134-generic Ubuntu 22.04 64-Bit linux-image-5.15.0-186-generic Ubuntu 22.04 64-Bit linux-image-5.15.0-185-generic
Fixes
-
Resolved an edge case where dgdaemon could attempt to classify itself, causing an agent deadlock and potentially making the system unresponsive.
-
Resolved an issue where the dgagent-owned process keeps crashing when dgagent is installed in a custom directory.
Server (DGMC)
Version: 9.2.0
August, 2026
New Features
-
The DGMC installer now uses Advanced Installer, providing a modern installation experience with updated Fortra branding, replacing the legacy Digital Guardian branding.
Before installing DG Server, review the DG Server Software Requirements section of the eDLP Installation and Upgrade Guide 9.2.0 available on Fortra Support Portal to verify that your environment meets all required software prerequisites.
-
Added support for existing DGMC APIs in on-premises deployments, enabling customers to automate the management of Control Policies and Rules. This improves integration with existing automation workflows, streamlines communication between systems, and reduces the manual effort required to manage and maintain Control Policies and Rules.
-
Enhanced DomainFlags resource file processing in DGMC to improve performance when updating large files, reducing the time required to apply changes.
Fixes
-
Resolved an issue where updating large DomainFlags resource files caused significant delays in DGMC.
Fortra
Endpoint Manager
August 5, 2026
Enhancements
-
Added Fortra Appliance (FA) support bundle collection and download to the Endpoint Manager log download workflow.
-
Endpoint Manager now displays Cloud Data Protection tenant and node name details for configured modules in the Edit Module drawer.
-
Added Cloud Data Protection node provisioning to the Endpoint Manager UI configured module creation workflow.
-
Endpoint Manager now displays the Fortra Appliance version in the Overview section when a Fortra Agent endpoint is selected.
Fixes
-
Fixed an issue in the Endpoint Manager UI where assigning an endpoint to a group through search cleared existing group members. The group now retains all members when updated.
-
Fixed a "Schema mismatch" error that prevented users from attaching a DSPM Scanner module to an endpoint during package upgrades.
-
Fixed an issue where Endpoint Manager could target the wrong tenant when a Platform tenant was linked to multiple Endpoint Manager tenants.
-
Upgraded components to improve security and stability.
Fortra Appliance
Version 3.1.1
August 11, 2026
-
By default, the appliance restarts automatically shortly after an upgrade is successfully prepared. Administrators can configure a manual restart instead.
-
Do not submit the same upgrade repeatedly while a restart is pending.
-
Secure Shell (SSH) access remains disabled after upgrading to Fortra Appliance 3.1.1.
-
To reset the local web interface administrator password, sign in to the appliance's limited console as fmasetup and run webui-admin-password-reset.
Enhancements
-
Improved appliance upgrades to preserve network configuration, system identity, administrative access settings, and other essential configuration.
-
Added automatic restart handling after a successful appliance upgrade. Administrators can disable automatic restart when a manually scheduled restart is preferred.
-
Improved recovery when an appliance IP address changes.
-
Improved reliability when restoring service after network or firewall configuration changes.
-
Improved status reporting for managed appliances and Control Center connectivity.
-
Added diagnostic bundle support for FMA appliance troubleshooting, including appliance deployments used as DSPM OnNetwork scanner nodes.
-
Added Syslog forwarding for audit and system events using configured logging destinations.
-
Improved air-gapped application uploads. Upload progress remains visible after navigating away, and interrupted uploads can be resumed safely.
-
Improved application deployment status reporting so active operations are no longer shown as completed before they finish.
-
Improved application package cleanup and storage management.
-
Strengthened protection of appliance sign-in credentials by requiring secure connections for production authentication.
-
Locked bootstrap account settings after initial setup and added UI guidance to prevent unsupported post-bootstrap changes.
-
Reduced appliance console access while retaining a limited, authenticated password-recovery workflow.
-
Further restricted external access to internal appliance services.
-
Removed unnecessary remote-management components from delivered appliance images.
Bug Fixes
-
Fixed upgrade failures and configuration loss associated with DHCP-based appliances.
-
Fixed upgrade interruptions that could leave an appliance waiting for a restart.
-
Fixed an issue that could cause a "502 Bad Gateway" response during web interface sign-in.
-
Fixed login availability issues caused by internal network access rules.
-
Improved reliability when restoring service after network or firewall configuration changes.
-
Fixed storage changes that could inadvertently remove or reduce existing application storage allocations.
-
Added capacity checks to prevent storage growth that the appliance cannot safely accommodate.
-
Fixed application upload progress and recovery behavior.
-
Fixed misleading deployment and execution statuses.
Fortra platform
August 19, 2026
New Features
-
Added notifications to the Platform UI. Users can view platform-generated and platform-integrated app notifications from the bell icon, filter notifications, dismiss them, mark them as read, and view notification details.
Enhancements
-
Added support for incrementally releasing features, including targeting specific customers or users.
-
Improved the Accounts page search in Platform Manager to support partial matches by account name path and exact matches by account ID.
-
Improved account search to automatically filter by the current tenant's name path when a tenant is already being impersonated.
-
Added support for sending notifications to specific users by email address.
-
Added configurable expiration for notifications, allowing notification creators to set how long notifications remain available.
-
The Branding feature now appears only for accounts that are entitled to configure custom branding.
-
Extended CSV export requests with a new envelopeColumns parameter, allowing users to select document metadata fields, such as ID and created and updated timestamps, for inclusion in exports.
-
Removed deprecated tenant provisioning and deprovisioning endpoints that required a Tenant-Context header.
Bug Fixes
-
Fixed an issue where users were not impersonated to the correct tenant when logging in through a URL containing a tenant parameter.
-
Fixed an issue where the tenant parameter was not preserved in Platform Manager URLs when editing or adding items.
-
Fixed an issue where the Users drawer intermittently displayed a previously assigned account after it had been removed.
-
Fixed an issue where assigning a role to all accounts did not correctly select all tenants under the parent.
-
Fixed an issue where tenant and product tenant ID values were incorrect in URL query parameters when navigating between applications.
-
Fixed an issue where the Environment Switcher did not display available tenant options during impersonation.
-
Fixed an issue where users saw a 404 page when logging in through their Okta dashboard tile.
-
Fixed an issue that caused Cloud Data Protection users to receive a 403 error when opening an accessible tenant link in a new browser tab.
-
Fixed an issue where the Accounts table displayed incorrect results when users combined a text search with status or type filters.
-
Fixed an issue where users were repeatedly prompted to verify their email when logging in with custom SSO.
-
Upgraded components to improve security and stability.
Fortra VM On-Premises
Version 7.0.6.1 Build 665
August 10, 2026
Enhancements
-
Updated consolidated vulnerability checks. For more information, see the Vulnerability Dictionary in Fortra VM On-Premises.
Globalscape
EFT Health Check Agent
Version 1.10.0
August 21, 2026
New and Improved
-
Added health and performance monitoring for the EFT Windows service and process, including restart detection.
-
Added monitoring for Automate 2026 and legacy Automate runtimes, including service/process status, CPU, memory, handle, thread, and process-age metrics.
-
Significantly improved Metrics page performance and memory usage through server-side aggregation and more efficient database queries.
-
Improved Metrics loading indicators, navigation behavior, unavailable-value display, and database contention handling.
Security Enhancements
-
New installations listen on localhost only by default.
-
Added an “Allow remote connections” option under Web settings for environments that require network access.
-
Protected support-bundle generation and download endpoints with authentication.
-
When no JWT secret is configured, the application generates a secure temporary secret in memory. Sessions will require a new login after the service restarts.
Connectivity and Support
-
Added optional HTTP/HTTPS proxy support for update checks through the UpdateCheck:HttpProxy setting.
Resolved Issues
-
Fixed UNC share paths containing spaces being displayed and validated with %20, which could incorrectly report an accessible network share as inaccessible.
-
Improved Metrics database reliability during concurrent collection and viewing.
-
Corrected missing-data cells so unavailable metrics are no longer represented as zero.
EFT Arcus
Version 8.3.3.569
August 24, 2026
EFT Arcus 8.3.3.569 delivers significant improvements across security, automation, administration, REST API capabilities, cloud integrations, Workspaces, ARM reporting, and platform modernization.
Key Highlights
-
Multi-factor authentication (MFA) support for EFT administrators.
-
FIPS 140-3 compliant SSL and SSH support.
-
Expanded REST API and Web Admin functionality.
-
Fortra Threat Brain integration.
-
Updated OpenSSL/OpenSSH libraries.
-
Enhanced Secure Data at Rest reliability.
-
Major Automate Workflow Module (AWM) enhancements.
-
Support for Windows Server 2022 and 2025.
-
Numerous stability, scalability, and cloud connector fixes.
New Features
EFT Administration
-
Added support for multiple SSH host keys per site.
-
Added support for Fortra Threat Brain integration.
-
Added support to override MFA policies for Web Admin and REST API.
-
Added support for disabling EFT administrators after a period of inactivity.
-
Added support for MFA (2FA) for EFT administrators.
REST API
-
Added support to refresh user databases through the REST API.
-
Added MFA support to the /v1/authentication endpoint.
-
Added support for Virtual Folder management enhancements.
-
Expanded HA replication support for REST-managed configurations.
Web Admin Client (WAC)
-
Added MFA support in Web Admin.
-
Added Threat Brain widget integration.
-
Added support to display user statistics.
-
Added support to change EFT administrator passwords.
-
Added the ability to determine EFT site authentication type.
Workspaces / WTC
-
Added support to change workspace ownership.
-
Added the ability to configure default workspace expiration values.
-
Added display of workspace expiration information in WTC.
-
Added support for CSP Level 3 strict-dynamic.
-
Improved Workspace policy handling and expiration management.
Security & Compliance
-
Added FIPS 140-3 compliant SSL support.
-
Added FIPS 140-3 compliant SSH support.
-
Added warnings when weak RSA 1024 keys are used in FIPS mode.
-
Added enhanced MFA and administrator security controls.
Enhancements
Administration
-
Added Event Rule Name visibility in Transfers as Client UI.
-
Added Advanced Properties JSON file to Support Bundles.
-
Added support for Windows Server 2022 and 2025.
-
Improved secure data at rest configurations.
-
Improved HA Active-Active messaging and diagnostics.
ARM
-
Added SSH fingerprint logging for inbound connections.
-
Added new ARMImportSpeed Advanced Property to control SQL import throughput.
-
Improved ActionGUID database optimization.
-
Added LocalFileName and RemoteFileName fields to tbl_actions.
-
Added ActionID linkage to tbl_ClientOperations.
-
Improved ARM report rendering and database processing.
Automate Workflow Module (AWM)
-
Upgraded Automate Desktop integration to v2025.
-
Improved AML conversion handling.
-
Removed DotNetZip dependency.
-
Improved Loop File Contents performance and resolved memory leak issues.
-
Added ExtractFilePathWithDrive function.
-
Improved handling of large files and network paths.
-
Enhanced Base64 compatibility with external tools.
-
Added support for shared mailbox AutoDiscover username field.
-
Improved task queue handling to wait indefinitely instead of timing out.
-
Improved CSV, XML, HTTP, SQL, and Excel activity handling.
-
Added standardized session-related error codes.
Cloud Connectors
-
Updated AWS SDK to v1.11.722.
-
Updated Google Cloud SDK libraries.
-
Updated Azure SDK implementation.
-
Updated AWS region list.
-
Improved encrypted upload compatibility across cloud providers.
OpenSSL / OpenSSH / OpenPGP
-
Updated Non-FIPS OpenSSL to v3.6.1.
-
Updated FIPS OpenSSL to v3.1.2.
-
Updated OpenSSH to v9.8.1.0.
-
Updated OpenPGP library to v2024.
Installer & Platform
-
Added improved messaging for HA Active-Active cluster setup.
-
Updated OLE SQL Driver to v19.3.5.
-
Removed bundled local help files in favor of web-based help.
Logging
-
Added syslog support by default.
-
Improved Automate workflow conversion logging.
-
Expanded diagnostic and support bundle data collection.
WTC
-
Updated Angular framework to v19.
-
Implemented OWASP Anti-CSRF recommendations.
-
Updated branding and UI styling.
-
Improved localization and translated text handling.
Security Updates
Security Library Updates
-
Patched CVE-2025-15467 by upgrading OpenSSL to v3.6.1.
-
Improved SSL certificate validation and FIPS enforcement.
-
Improved password policy defaults for PCI-focused environments.
-
Added stronger MFA and authentication controls.
Compliance Improvements
-
Expanded FIPS 140-3 compliance support.
-
Improved handling of weak SSH/SSL cryptographic configurations.
-
Enhanced administrator inactivity controls.
Cumulative Resolved Issues Included in 8.3.3.569
The following issues were resolved in EFT releases after 8.1.1.16 and are included in EFT 8.3.3.569. Some issues may have been introduced in intermediate 8.2.x or 8.3.x releases and may not be present in EFT 8.1.1.16 environments. They are listed here because they are part of the cumulative fixes included in the target release.
EFT Administration
-
Fixed crashes related to unsupported PKCS12 certificates in FIPS mode.
-
Fixed incorrect SSL expiration notification emails.
-
Fixed issues with password expiration notifications.
-
Fixed issues launching EFT online help from Admin GUI.
-
Fixed admin session termination during non-certified SSL imports.
-
Fixed active session display inaccuracies.
Secure Data at Rest (Encryption)
-
Fixed file corruption when downloading encrypted files using WinSCP or Java-based clients.
-
Fixed partial encryption/decryption corruption in eftencrypt.exe.
-
Fixed data corruption introduced in EFT 8.3.2.565 configurations.
-
Improved encrypted cloud upload handling across Google Drive, Google Cloud, Amazon S3, and Azure Blob Storage.
REST API
-
Fixed failures creating or patching Virtual Folders.
-
Fixed incorrect responses and NULL return values.
-
Fixed keep-alive response handling.
-
Fixed admin-user PATCH validation issues.
-
Fixed issues creating VFS cloud resources.
-
Fixed missing fields and incorrect boolean responses.
-
Fixed replication issues in HA clusters.
-
Fixed REST crashes caused by invalid connection profile data.
Cloud Connectors
-
Fixed Azure Blob SAS token connectivity issues.
-
Fixed Azure-related EFT service crashes.
-
Fixed S3 Compatible endpoint upload failures.
-
Fixed false failure reporting for Azure Blob downloads.
Automate Workflow Module (AWM)
-
Fixed queue cleanup issues for completed workflows.
-
Fixed performance counter inaccuracies.
-
Fixed FTP Preserve Date/Time behavior.
-
Fixed Excel macro execution prompts.
-
Fixed Task Builder freezes with cipher selections.
-
Fixed memory leaks in HTTP loop activities.
-
Fixed GZIP decompression handling.
-
Fixed XML cleanup resource handling.
-
Fixed CSV quoted-header parsing and SQL DATE conversions.
-
Fixed simultaneous task variable resolution issues.
-
Fixed Active Directory username migration issues.
ARM
-
Fixed multiple report formatting and logging issues.
-
Fixed missing Rename/Move audit logging.
-
Fixed report refresh issues.
-
Event Rules / OpenPGP / SMTP.
-
Fixed OpenPGP sharing violation failures.
-
Fixed SMTP connection cleanup issues.
-
Fixed password email notification failures.
-
Fixed SFTP timer event recovery after network reconnect.
SFTP / SSH
-
Fixed service crashes under heavy proxy protocol traffic.
-
Fixed memory exhaustion issues under high connection load.
-
Fixed Remote Agent SFTP compatibility issues with legacy ciphers.
WTC / Workspaces
-
Fixed portal rendering issues when exceeding Workspace policies.
-
Fixed translated text issues.
-
Fixed 412 Precondition errors in developer tools scenarios.
-
Fixed email verification issues involving special characters.
Platform and Compatibility Changes
-
Updated Dependencies.
-
OpenSSL upgraded to v3.x family.
-
OpenSSH upgraded to v9.8.1.0.
-
Angular upgraded to v19.
-
Updated AWS, Azure, and Google Cloud SDKs.
-
Updated OLE SQL driver and installer components.
Known Issues
-
Site propagation may fail when custom email templates exist on the source site.
-
Some environments using Automate Workflow Engine (AWE) may experience intermittent performance degradation during periods of high workflow concurrency or heavy task execution loads. Symptoms may include delayed task execution, increased queue processing times, or elevated CPU and memory utilization. This issue has been identified and is scheduled to be resolved in the next Arcus release.
-
Remote Agent (RAM) instances that have one or more Templates configured with an Update Interval set to Near Real-Time may encounter failures during upgrade, requiring manual intervention to complete the upgrade.
-
Workaround: To reduce the likelihood of this issue, it is recommended to configure the Template Update Interval to 30 minutes or longer.
Powertech
Version 8.1.0.10
August 17, 2026
Fixes
-
Removed deprecated http header X-XSS-Protection.
-
Restrict H2 database access to the BRS process.
-
Upgraded security dependencies.
For more information, including CVE references for fixes, see the README file.
Version 9.0.0.1
August 17, 2026
Updates
-
Added support for Red Hat EL/Oracle EL 10.
Fixes
-
Removed deprecated http header X-XSS-Protection.
-
Restrict H2 database access to the BRS process.
-
Upgraded security dependencies.
For more information, including CVE references for fixes, see the README file.
Powertech Risk Assessor
Version 3.4
August 3, 2026
Enhancements
-
Added a new "NetServer Attributes report" (SKYNETATTR). This report identifies the SMB versions that are enabled and their configuration properties.
-
Added a new "Powerful Profiles TOTP Report" (SKYTOTPADM) or systems running OS version 7.6. This report highlights user profiles with *ALLOBJ and *SECADM Authority that are not secured via 2-factor authentication. Summary information has also been added to the SKYASSESS report.
-
Added a new "User Profile TOTP Configuration" report (SKYTOTPUSR) for Systems running OS version 7.6, that have been enabled for TOTP 2-factor authentication. This report lists all user profiles, indicating whether TOTP is enabled.
-
Added a new option to consolidate all assessment reports into a single IFS location. Reports are now stored in a timestamped directory under /SkyView/Risk Assessor/yyyy-mm-dd_hhmmss/, eliminating the need to retrieve results from both spooled output and the IFS and simplifying report management.
-
Risk Assessor now allows individual reports to be run independently, enabling targeted assessment of specific security or configuration areas. A toggle for Select All and Unselect All simplifies report selection, helping users focus only on the reports most relevant to their current improvement efforts.
Fixes
-
Fixed an error on the *IOSYSCFG Report, where Powerful Users were not listed if the obtained their authority through a group profile.
-
Fixed an error where the SKYGRPUSRS report was not generated if no Group Memberships existed.
-
Fixed an issue where the User Profiles with Default Passwords report has wrong data.
-
Fixed an issue where the User Profiles with EIM Associations report was returning an error.
-
Fixed an issue where the Weak Password Report may not have been produced.
-
Updated the SKYASSESS report formatting to improve clarity
Secure Collaboration (Vera)
Version 3.25.5
August 2026
Security Fixes
-
Authentication Security Hardening
-
Strengthened authentication across web, desktop client, and document-access workflows by binding sign-in callbacks and token redemption to the initiating session and enforcing one-time use of authentication transactions.
-
Security Awareness Training
Version: 1.131
August 19, 2026
Enhancements
-
Several accessibility issues could affect navigation and content access for users of assistive technologies. We have improved keyboard navigation, screen reader support, color contrast, focus indicators, zoom and reflow behavior, and the accessibility of course controls, status indicators, and system messages to enhance WCAG compliance and provide a more accessible user experience.
-
When a new course is created, the default Course Status Option is now selected based on whether the course includes an evaluation. Courses without an evaluation default to Not Started / In Progress / Completed, while courses with an evaluation default to Not Started / In Progress / Passed. Existing courses are not affected.
Fix
-
Users were unable to view or download saved reports when a user type filter was applied, resulting in an error. This issue has been resolved, and reports can now be viewed and downloaded successfully with user type filters enabled.
Version: 1.130.1
August 05, 2026
Fix
-
Users were unable to access and complete training content on iPhone devices. This issue has been fixed.
Titus
DCS for Windows
Version 6.1.3
August 3, 2026
Fixes
- Fixed an issue where changing a Microsoft Information Protection (MIP) label in a Microsoft Office application could cause the Classification Selector to open as read-only if the resulting DCS metadata was invalid.
- Fixed an issue where the TCOSaveAsPDF custom action did not include MIP metadata in the generated PDF.
DCS One (Customer-hosted)
Version 5.2.1
August 14, 2026
Fixes
- Resolved an issue where configured header content for the Apply header/footer action overlapped when it contained multiple lines in Excel Online.
- Resolved an issue where configured header content for the Apply header/footer action did not display correctly in PowerPoint Online.
DCS One (SaaS)
Version 2026.08
August 14, 2026
Fixes
- Resolved an issue where configured header content for the Apply header/footer action overlapped when it contained multiple lines in Excel Online.
- Resolved an issue where configured header content for the Apply header/footer action did not display correctly in PowerPoint Online.
DCS Policy Manager (Customer-hosted)
Version 5.3.3
August 13, 2026
Fixes
-
Improved LDAP group loading for configuration targeting to reduce long wait times in environments with large numbers of Active Directory groups. Target Groups now load in batches of up to 100, with options to load additional groups or search for groups after entering at least three characters.
DCS Policy Manager (SaaS)
Version 2026.08
August 21, 2026
New Features
-
Added support for configuring Policy Templates. You can select a Policy Template for a Configuration or convert it to a Policy when you need to configure additional settings. The first supported Policy Template type is Email Domain Clearance, which defines how the DCS client responds when users try to send emails to configured domains.
-
For DCS for Windows, added support for STANAG 4774 labeling. See the Data Classification Suite for Windows STANAG Integration Guide for instructions. Configuration requirements include:
-
An Ultra Plus license is required.
-
Configure Schema Field general settings for Category type and Label conflict resolution.
-
Configure App Settings under STANAG 4774 Settings to enable features and enter user interface text.
-
-
For DCS for Windows, added support for the Fortra DLP Analytics and Reporting audit logger. Select this logger and configure settings under DCS Audit Settings App Settings.
NOTE:-
DCS Services Layer is required to forward DCS for Windows audit events to Fortra DLP Analytics and Reporting. In customer-hosted environments, you must deploy DCS Services Layer. In SaaS environments, you do not deploy DCS Services Layer.
-
In addition to downloading the TCPG file, you must publish the Configuration in DCS Policy Manager so that DCS Services Layer has the information it needs to forward audit events to DLP Analytics and Reporting.
-
-
For DCS for Windows, added support for the following actions:
-
Add BCC recipients
NOTE: When importing TCPG files from the DCS Administration Console to DCS Policy Manager, BCC Auditing actions are imported as Add BCC recipients actions. -
Apply Seclore protection
NOTE: See the Data Classification Suite for Windows Seclore Integration Guide for instructions. -
Remove bookmarks
-
Set attachment classification
-
-
For DCS for Windows, added support for the following App Settings:
-
Body Labeling (under Metadata Handlers)
-
Australian Email Protective Marking Standard (under Metadata Handlers)
-
Trusted Labels
-
-
For DCS for Windows, added selections under Azure Cloud Type and configurable Policy Cloud Endpoint Base URL and Protection Cloud Endpoint Base URL fields for custom Azure cloud deployments under Microsoft Sensitivity Label Interoperability App Settings.
-
Added support for downloading a Schema View JSON file. The file contains Namespace and Schema View information.
Enhancements
-
Updated the DCS Policy Manager user interface to meet Fortra standards.
-
Added support for entering Target Group names. You can enter names that are not listed or filter the displayed options.
-
Added support for reordering Subrules.
-
Added the Semitransparent parameter for the Apply watermark action.
-
Expanded Document.CustomProperty support across applicable Word, Excel, and PowerPoint policy events.
-
Added support for additional file types for the Microsoft Information Protection (MIP) adapter.
-
When importing TCPG files from the DCS Administration Console to DCS Policy Manager, Apply HTML Header/Footer actions are imported as Apply advanced header or footer actions. Supported parameters in both configuration products are automatically mapped during the import.
-
Renamed Set custom property to Set custom property – scans to distinguish this DCS for Data at Rest (DaR) action from the similar action supported by DCS for Windows and DCS One. No configuration updates are required.
-
Updated the confirmation dialog for exporting DCS Policy Manager data to a POLMAN file to warn that previous versions of Policy Manager might not support all features included in the file.
Fixes
-
Resolved an issue where rules appeared in a different order after exporting and then importing a POLMAN file.
-
Fixed configuration import issues that affected Environment property conditions, alert descriptions, and overlapping schema mappings.