Monthly Release Notes - September 2026
Boldon James
Email and Office Classifier
Version 3.22.3
September 25 , 2026
Fixes
-
Resolved an issue where changes made by a delegate to an individual occurrence of a recurring Outlook meeting did not synchronize correctly with the organizer's calendar. The update preserves Classifier labels and policy controls when a delegate modifies or cancels an individual occurrence.
-
Resolved an interoperability issue between Email & Office Classifier and the Cryptovision GreenShield add-in. When Classifier cancels a send operation during a policy check, users can edit, close, or resend the message without interference from the GreenShield add-in.
-
Resolved an issue where changes made to an email label using the folder view labeling feature did not persist to the email.
Digital Guardian
nDLP Appliance
Version: 14.0
September, 2026
New Features
-
This release modernizes the nDLP user interface and middleware framework across several core product areas, including Protect Data, Register Data, Discover Data, Manage System, Manage Appliances and Agents, and Dashboard and Reporting. The updated framework improves performance, security, scalability, and integration across nDLP components while providing a more consistent and responsive user experience.
-
OAuth 2.0 authentication is now supported for sending email notifications through Microsoft Office 365. Administrators can configure Office 365 OAuth from the Email Notification Settings page. Existing SMTP Relay configurations remain supported and do not require changes.
Refer to Setting Up a Notification Server > Using Office 365 OAuth in the Digital Guardian Appliance 14.0 Administrator’s Guide.
-
nDLP Appliance now displays a banner on the View Status > Dashboard page when the overall incident count reaches the configured threshold, before policies are disabled. By default, the threshold is 50 million incidents. A banner also appears when system volume reaches the predefined threshold for cleaning up copy-retention files.
-
In this release, the DG Appliance operating system is upgraded from Rocky Linux 8 to Rocky Linux 9. This upgrade provides an updated operating system foundation and improves platform security by addressing vulnerabilities associated with the current base OS.
For more information, refer to the nDLP_Migration_Guide_for_11.9_12.x_13.x_14.x.
-
nDLP updates the Micro Focus KeyView components to version 26.x. The updated components include fixes and improvements provided in the newer vendor version.
-
Enhanced Discover scans to retrieve file owner information from document properties when the information is unavailable from the file system, providing an additional source for identifying file owners across file types.
Fixes
-
Resolved an issue where ICAP policies did not block file uploads to websites when the uploaded files matched the configured policy conditions.
-
Resolved an issue where uploading a new server certificate through the DG Appliance management console did not update the Nginx certificate, causing the previous expired or invalid certificate to remain in use.
-
Resolved an issue where the Classification Entity Frequency in ARC did not match the corresponding Data at Rest discovery match count reported by the nDLP appliance.
Agent for macOS
Version: 10.1.2
September, 2026
New Features
-
In this release, Agent for macOS has been certified to run on Apple macOS 27 (Golden Gate). Starting with macOS 27, users may need to grant Accessibility permission to enable certain Agent capabilities. For more information, see Accessibility Permission Changes in macOS 27 under Critical Notices in the Digital Guardian Agent for macOS 10.1.2 Release Notes.
Fixes
-
Resolved an issue that caused the DgSessionSvc and RME processes to crash on macOS 27 when ADE was enabled.
For information about known issues and critical notices for the macOS Agent 10.1.2 release, refer to the Digital Guardian Agent for macOS 10.1.2 Release Notes, available at Fortra Support Portal.
Agent for Windows
Version: 12.0.0
September, 2026
New Features
-
This release introduces an asynchronous Content Inspection workflow that improves performance, scalability, and resiliency during file operations.
The updated workflow queues and coordinates inspection requests, reducing duplicate inspections and improving the handling of high-volume file activity. Dedicated DgACI worker processes perform content inspection independently from the DG Agent process, improving stability and allowing inspection processing to recover if a worker encounters an issue.
These enhancements are designed to preserve the existing user experience and policy outcomes while improving inspection throughput and recovery for file inspection in DG Agent for Windows.
-
Introduced conflict-detection operational alerts for Digital Guardian processes. The agent can now generate DGMC alerts when third-party software interferes with DG processes, such as through remote thread creation, process access attempts, or third-party DLL loads. These alerts help identify potential software compatibility issues where the third-party product may need to be configured to exclude Digital Guardian. This capability is detection-only and provides greater visibility into potential third-party software conflicts and process interference. It does not introduce new blocking or enforcement actions.
Added configurable options to control how often conflict-detection alerts are generated and to exclude trusted third-party DLLs from alerting, helping reduce alert noise. The following configuration settings have been added for conflict-detection operational alerts:
ConflictDetectOpAlertPeriod
-
Controls the frequency of conflict-detection alerts (default: 24 hours / 1440 minutes).
-
Set to 0 to disable alerts.
ConflictDetectDllExceptionList
-
Allows specified DLLs or DLL/company combinations to be excluded from alerting.
-
Entries without a company value are matched by DLL name only.
-
Default DLL exception list format: dllname,companyname;
-
-
Digital Guardian Agent for Windows now enables the mini-filter driver interface by default for both DGWip and non-DGWip file I/O operations. This enhancement improves performance, reliability, and compatibility by using the modern Filter Manager mini-filter architecture for file I/O operations.
-
Added support for reading MIP labels from files with unsupported extensions using file type detection. For existing files, a user action, such as copying the file, is required to trigger re-inspection and MIP label reading.
-
This release enhances compatibility with WinUI/AppRuntime-based Windows Store applications by adjusting window hook behavior for supported applications, helping reduce application instability and improve interoperability with these applications.
-
In this release, content inspection operations have been moved to a dedicated process, dgaci.exe. This enhancement improves the reliability of content inspection operations and enables more efficient recovery from inspection-related issues.
NOTE: Customers should add dgaci.exe to any required exception lists. Existing exceptions for kvoop.exe remains required for DgScan operations and should not be removed from existing exception lists. -
Improved ACI timeout handling so that when no timeout is explicitly configured, the agent automatically calculates an appropriate inspection timeout using the built-in heuristic.
-
The dirctrl.dat documentation has been updated to accurately reflect the configuration sections supported by DG Windows agents. The documentation section now identifies obsolete legacy sections and includes version information for newer sections such as ACI2 and FASTPATH.
Fixes
-
Resolved an issue identified by Microsoft Driver Verifier that could lead to a potential deadlock due to inconsistent lock ordering during process updates.
-
Resolved an issue that caused crashes in certain Windows store applications built on WinUI/AppRuntime frameworks.
-
Resolved an issue where classifications could be missing for archive files during File Copy and File Archive operations when archive inspection timed out.
-
Resolved an issue where the agent could misinterpret redacted browser address-bar values as destination paths.
-
Resolved an issue where images could remain in a destination Microsoft Word document after a block action and prompt were triggered during a copy-and-paste operation.
-
Resolved an issue where process flags were not applied consistently to applications launched from network share paths, while the same applications launched from local file system paths were processed correctly.
-
Resolved an issue Fixed DGMinFlt.sys version metadata so Driver Verifier shows provider as Digital Guardian, Inc. instead of the default WDK provider string.
For additional details on resource file changes, refer to the Digital Guardian Agent for Windows 12.0 Release Notes under the Resource File Changes section on Fortra Support Portal.
Fortra
Fortra Appliance
Version 3.2.1, build 74
September 25, 2026
-
You can upgrade to Fortra Appliance 3.2.1 only from version 3.2.0 by using the supported appliance OS upgrade package.
-
After upgrading an appliance with a static management address, confirm the saved network settings and appliance availability after the reboot.
Enhancements
-
Resolved issues that could prevent initial appliance setup from completing in environments without DHCP or Internet access.
Fixes
-
Saved static network settings are now retained during appliance startup, preventing fallback to the default network configuration.
Version 3.2.0, build 68
September 16, 2026
-
Direct upgrades to Fortra Appliance 3.2.0 are supported only from Fortra Appliance 3.1.2.
-
After an upgrade is successfully prepared, the appliance schedules an automatic restart. Do not submit the same upgrade again while a restart is pending.
-
Administrators who know their current local password can change it from the user menu. If an administrator cannot sign in, open the Fortra Appliance console in VMware vSphere, sign in with the fmasetup account, and run webui-admin-password-reset.
Enhancements
-
Authenticated local administrators can now change their password from the account menu without accessing the virtual machine console.
-
Updated all instances of "Fortra Managed Appliance" and "FMA" to "Fortra Appliance" and "FA" in the UI.
-
Network configuration now supports valid IPv4 management addresses, including globally routable addresses, while rejecting addresses that conflict with reserved internal networks.
-
Single-node appliances now provide a planned management address change workflow that safely applies the new address, preserves application data, and restarts the appliance when required.
-
Server certificates are automatically reconciled after a management IP address or hostname change so they reflect the active appliance endpoints.
-
A support-guided recovery-shell command is now available from authenticated local or serial fmasetup console sessions. The workflow requires an explicit risk acknowledgment before providing full base OS recovery access.
Fixes
-
Fixed intermittent and misleading "Needs attention" and "Not configured" status indicators in Control Center for registered managed appliances.
-
Fixed an API timeout error when generating support bundles from the Fortra Appliance UI.
-
Fixed an issue that prevented Fortra Agent service accounts from updating aggregate configuration in managed mode.
-
Fixed an issue where the Applications page initially displayed empty application details and missing package upload controls in air-gapped mode.
-
Fixed UI rendering and state update issues when updating applications in air-gapped mode.
-
Fixed an issue where multiple license files could not be uploaded and applied consecutively from the Applications settings page without leaving the page.
Fortra platform
September 22, 2026
Fixes
-
Fixed an issue where administrative users could see the "Type" filter on the Products page.
-
Fixed an issue that prevented administrators from enabling or disabling social and email login providers from the "Login Options" table in Platform Manager.
-
Fixed an issue where disabling a custom identity provider in Platform Manager did not immediately save or display its disabled state.
-
Fixed an issue where users with read-only account permissions saw editing options instead of the view-only account details.
-
Fixed an issue where filters in the "Assign Account" dialog did not populate until the user entered a search term.
-
Fixed an issue where "Add Account" was disabled when the Accounts page was opened in a new browser tab.
-
Fixed intermittent failures when users were added to or removed from groups at the same time.
-
Improved transaction retry handling to prevent temporary database conflicts from returning 500 or 503 errors.
-
Upgraded components to improve security and stability.
September 3, 2026
Enhancements
-
Improved user search to include additional attributes, such as email address and display name, making it easier to locate specific users.
-
Improved the visual consistency of UI dialogs across the platform.
Fixes
-
Upgraded components to improve security and stability.
Fortra VM
Version 7.10.2
September 18, 2026
Fixes
-
Reduced latency for accounts in the UK region.
Version 7.10.1
September 4, 2026
Fixes
-
Fixed an issue that caused a 401 error when users attempted to reset an expired password.
-
Fixed an issue in frontline.cloud where clearing notifications prevented new notifications from appearing.
-
Fixed an issue where PCI bundle reports did not display correctly.
-
Fixed an issue where PCI report generation requested out-of-scope domains.
Version 7.10.0
September 2, 2026
New Features
-
Added interactive Swagger documentation for the Fortra VM REST API. Swagger lets users explore available API endpoints, review request details, and test API calls directly from Fortra VM. To access the documentation, go to "Support" in the left menu and select "REST API Guide."
-
Added bulk controls to the Agent page so users can activate, deactivate, or uninstall multiple agents at once.
Enhancements
-
Updated UI styling for frontline.cloud and on-premises users, including fonts and visual elements, while maintaining the existing layout and control placement.
-
Improved dark mode across all deployment types.
-
Added a new preset scan policy: "Full TCP/UDP Port Scan."
-
Updated the login page for frontline.cloud and on-premises users.
-
Added a requirement for extra audit URL regexes in web application scans to start with http.
Fixes
-
Improved report title readability in dark mode.
-
Improved Network Map readability in dark mode.
-
Display mode preferences now persist across sessions and refreshes.
-
Display mode remains consistent when switching accounts.
-
Display mode changes now stay synchronized across the application.
-
Remediation Overview discovered and fixed vulnerability counts now match.
-
Fixed filtering in Threat Summary - Vulnerabilities with Recent Threat Activity.
-
Improved vulnerability age calculation accuracy for recurred vulnerabilities.
-
Improved reliability when generating translated reports.
-
Disabled report creation when no reportable data is available.
-
Updated report template headings to match other pages.
-
Scans now report an error when no scanner is available.
-
Improved reliability when recurring scan groups are created concurrently.
-
Scans now exit the launching state when all scan blocks fail.
-
Added clearer warnings when automatic web application scans are disabled.
-
Blackout windows are now enforced for on-premises RNAs.
-
Improved reliability of RNA support connections.
-
Resent user invitations are now delivered correctly.
-
Password setup and password reset submissions now complete successfully.
-
Region switching now completes correctly in standalone mode.
-
Developer information now displays the Fortra VM build version.
-
Vulnerability override search results now appear in the correct location.
-
Scans that use custom vulnerability overrides now complete successfully.
-
Fixed spelling in the "Network Scan Without Potentials" scan policy.
-
Scan group emails now include the correct Fortra VM link.
-
Label color options now include descriptive tooltips.
-
Breadcrumb labels now use consistent capitalization.
Fortra VM On-Premises
Version 7.10.3, build 535
September 23, 2026
Fixes
-
Fixed an issue that prevented some pages from loading in restricted network environments.
Version 7.10.1, build 517
September 17, 2026
Enhancements
-
Updated consolidated vulnerability checks. For more information, see the Vulnerability Dictionary in Fortra VM On-Premises.
Fixes
-
Fixed an issue that caused a 401 error when users attempted to reset an expired password.
Version 7.0.6.1 Build 669
September 3, 2026
Enhancements
-
Updated consolidated vulnerability checks. For more information, see the Vulnerability Dictionary in Fortra VM On-Premises.
GoAnywhere
GoAnywhere MFT
Version: 7.10.2
September 9, 2026
Enhancements
- Improved validation of Web User file access to prevent Secure Mail draft attachments from accessing files outside the user’s authorized home, virtual, or shared folders. This resolves the associated CVE.
Fixes
- Added AWS SDK v2 support for the approved S3 headers across direct and zero-byte uploads, multipart initiation, and Set Metadata copy operations.
- Fixed a compatibility issue with servers who advertise small SSH packet limits.
- Fixed an issue where algorithm fields in PGP, AS2, AS3, AS4, and Email tasks automatically selected a default.
- Fixed an issue with the Mina SSH provider under repeated usage causing memory leak.
- New GoAnywhere installations no longer trigger an unnecessary rebuild of the GoDrive audit-log index during initial startup.
- These fields are now editable and preserve blank values.
GoAnywhere Agents
Version: 2.6.2
September 9, 2026
Fixes
- Fixed an issue where interrupted transfers from an Agent to MFT could remain stalled while waiting for acknowledgements, preventing automatic resume from completing.
Updated Item
- Updated Netty from 4.2.12 to 4.2.15.
IBM Partnership
Backup, Recovery, and Media Services (BRMS)
Product 5770-BR2 Version: PTF 7.6 SJ10566, 7.5 SJ10565, 7.4 SJ10564
September, 2026
Enhancements
-
The CHGWEBBRM command has been enhanced with a new HTTPS() parameter support for strict transport security.
-
BRMS has been enhanced with new SQL services to change system, backup, and media policy information. See the BRMS wiki for more information at https://ibm.biz/brms-enhancements.
-
The BRMS web interface has been enhanced to show media duplicate information, restore support for configuration data and user profiles, and policy management for backup, system, and media policies. See the BRMS wiki for more information at https://ibm.biz/brms-enhancements.
Fixes
In version 7.4 and later:
-
Fixed issue where BRMS web interface remote support failed when using DRDA/DDM Conjoined Mutual Authentication.
-
Fixed issue where SETUSRBRM USAGE(*REMOVE) may fail with message MSGCPF4131.
-
Fixed issue where BRMS processing may repeatedly modify authorities on IFS directory /QIBM/UserData/BRMS/logs/brms, generating excessive AF and CA audit journal entries for the QBRMS user profile.
-
Fixed issue where control group backup entries *ALLCHGRCV and *ALLDTCRCV may fail with messages MSGCPF5009 and MSGCPF5034.
-
Fixed issue where INZBRM OPTION(*FLASHCOPY) STATE(*ENDBKU) may create DDM connections that cause delays when transferring QUSRBRM information.
-
Fixed issue where SQL service QUSRBRM.BACKUP_HISTORY may fail with message MSGCPD4019 when the backup history contains an IASP number greater than 99.
-
Fixed issue where media synchronization may fail in a secure DDM environment when the server authentication of the BRMS *ADMIN user profile does not have *ALLOBJ special authority.
Titus
DCS for Windows
Version 6.1.4
September 18, 2026
Fixes
-
Resolved an issue in Message Classification for Microsoft Outlook, where if Justification was enabled for an Attachment or Recipient Alert, selecting Send Anyway would generate duplicate Justification audit events (Event ID 3001) in the Windows Event Log.
Version 7.0
September 3, 2026
New Features
-
Added support for STANAG 4774 labeling in DCS for Outlook, DCS for Office, and DCS for Desktop. See the Data Classification Suite for Windows STANAG Integration Guide for instructions. Configuration requirements in DCS Policy Manager include:
-
An Ultra Plus license is required.
-
Configure Schema Field general settings for Category type and Label conflict resolution.
-
Configure App Settings under STANAG 4774 Settings to enable features and enter user interface text.
-
-
Added support for the following policy events in DCS Policy Manager:
-
Documents > On check policy
-
Documents > On save and send
-
-
Added support for the following actions in DCS Policy Manager:
-
Add BCC recipients
-
Apply Seclore protection
NOTE: See the Data Classification Suite for Windows Seclore Integration Guide for instructions. -
Password-protect Office attachments
-
Remove bookmarks
-
Set attachment classification
-
-
Added support for using customer-defined custom actions and custom conditions in DCS Policy Manager (Customer-hosted). This feature is not supported in DCS Policy Manager (SaaS). See the Data Classification Suite Extensibility User Guide for Policy Manager for instructions.
-
Added support for new or updated App Settings in DCS Policy Manager:
-
Under Metadata Handlers, added support for Body Labeling and Classifier Interoperability.
-
Added support for Trusted Labels.
-
Under Microsoft Sensitivity Label Interoperability, added support for additional Azure cloud types and the Policy Cloud Endpoint Base URL and Protection Cloud Endpoint Base URL fields for custom Azure cloud deployments.
-
Enhancements
-
Improved performance when sending audit events to loggers.
-
Improved performance when reading metadata in Outlook.
-
Added support for the Semitransparent parameter for the Apply watermark action.
Fixes
-
Fixed an issue with content validation checks that used custom regular expressions with Use Luhn Algorithm enabled.
-
Fixed an issue where an Apply Advanced Header/Footer action could remove an existing watermark.
-
Fixed a performance issue related to saving Microsoft Excel files to online drives.
-
Fixed an issue where users could bypass On Close policies in Microsoft Excel by selecting X to close an unsaved document.
-
Fixed an issue where DCS for Desktop did not retain classification metadata in image files.
-
Fixed a security vulnerability by updating the Microsoft Visual C++ Redistributable v14 included with the DCS for Windows installer.
-
Fixed an issue where footer body tags were not positioned correctly at the end of the email response body.
-
Fixed an issue with the alignment of the watermark when the header contains a table.
-
Fixed an issue where the Path element did not render correctly in audit event logs.
-
Fixed an issue where multiple Task Panes appeared in Microsoft PowerPoint while in Reading View.
-
Fixed an issue where forwarding an external meeting invite did not include the default classification.
-
Fixed an issue with the alignment of One Click buttons when using a DCS Administration Console configuration.
-
Fixed an issue where the classification of a meeting invite was not retained when the invite was canceled from the Folder View.
-
Fixed an issue that caused multiple classification prompts when sending meeting invites in Office 2024.
-
Fixed an issue where selecting and moving shapes on a Microsoft PowerPoint slide triggered exceptions in the DCS for Windows logs.