| Official release of LibraCyber Email Archiver v26.9: Monday, September 28, 2026, for customers in the Early Adopter Release Tier and for LibraCyber Cloud deployments. |
Major features
Release 26.9 centers on four key features that enhance how users search, understand, and work with archived data: a new semantic search layer, built-in proximity operators for full-text search, a fully localized end-user interface, and a redesigned Outlook add-in using the task pane.
Together, these updates make search more powerful and accurate, while making the platform more accessible for non-admin users across different languages and devices.
Semantic search
Previously, search was strictly lexical: a query would only match the exact words entered, so searching for invoice wouldn’t find messages mentioning bill, receipt, or credit note.
Release 26.9 adds an assisted, transparent semantic layer on top of the existing index.
After a user runs a search, the system suggests related terms, generated by a small language model running locally on the appliance.
Suggestions appear as cards, each representing a different meaning, so users can choose which related terms to include, require, or exclude.
Once confirmed, the expanded query is converted into standard advanced search conditions (word-list rules on subject and body) and run against the existing Manticore index.
No new search infrastructure is needed, and no data leaves the appliance: all processing happens locally.
This approach is intentionally transparent: users always see and control the expansion, so results are clear and understandable.
Semantic search is licensed and enabled per tenant.
The language model isn’t included in the appliance image: it’s delivered via nightly update sync to any appliance with a license for semantic search, so on a new appliance, the feature becomes available the day after the license is installed.
Once installed, it’s never downloaded again, and it remains even if the license later loses the feature, so renewals don’t trigger another download.
The email search page has been redesigned to support this.
The ten filter icon popups are replaced by a single Filters panel with a chip rail and Apply/Cancel buttons, so filters are only applied when you choose; Clear, Save search, and Fast export are now in the search bar next to it.
Pressing <kbd>Enter</kbd> now starts the search from any field in the form, not just the main full-text box.
Proximity operators in email search
Full-text search now supports proximity operators, letting users find terms that appear close together instead of anywhere in a message.
Using the familiar dtSearch-style W/N notation (like W/5 or W/10, meaning "these terms appear within N words of each other"), Archiver translates the request into Manticore’s native, order-independent proximity matching.
Both "words near each other" and "words NOT near each other" are supported, and the new operators are highlighted in the search interface so users can easily find and use them.
This fulfills a long-standing request for more precise, position-aware searching.
Multi-language user interface
The end-user interface is now fully localized, removing the previous English-only limitation for non-admin users.
Sixteen languages are included in 26.9 — Arabic, Chinese, Dutch, English, French, German, Hindi, Italian, Japanese, Korean, Polish, Portuguese, Russian, Spanish, Turkish, and Ukrainian — across the web app, Outlook add-in, and mobile app.
The interface language is chosen automatically from browser settings, with an optional local override.
Translations are updated automatically and reviewed by translators.
This makes the experience much more accessible for users worldwide, without adding extra setup for admins.
New Outlook add-in — task pane version
The Outlook add-in has been rebuilt using the modern task pane model, replacing the old popup view.
Moving the add-in to a task pane provides a more integrated, persistent, and reliable experience inside Outlook, following Microsoft’s latest add-in guidelines.
The manifest now opens the read surface as a task pane instead of the old dialog, and the compose-mode button — no longer supported by Outlook — has been removed.
The update also brings the add-in up to date with the popup version and adds more: the activity log for troubleshooting is accessible from the task pane, whether signed in or out; login tries the full MSAL chain (silent, popup) before failing; and date filters use the searching user’s time zone.
The add-in is localized in the same sixteen languages as the web app.
Because the manifest changed, Outlook reloads the add-in during the upgrade.
Features
- Redesigned email search bar: filters are grouped in a single Filters panel and applied together, with an active filter count and one-click Clear
- Relevance sorting: full-text results can be sorted by relevance, with per-field weighting that ranks matches in subject, senders, and recipients higher than matches found only in the body or attachments
- Search across multiple mailboxes: a new "in mailboxes" filter lets admins search a selected list of user mailboxes in one query, with multi-select autocomplete
- Consolidate duplicate results: when searching across multiple users, duplicate copies of the same email are combined into a single result, showing the match count and allowing you to switch between copies
- Top senders report: a new report shows, for each archived mailbox, the number of messages it has sent, helping admins spot high-volume senders to target with discard rules
- New resources page: CPU, RAM, and swap info has moved from the dashboard to a dedicated Settings > System > Status > Resources page, including summarized memory usage and estimated RAM needs; the dashboard now just shows a simple health status. The page is hidden on cloud appliances
- Audit log via syslog: the audit log can now be sent to an external syslog collector
- Policies reset job: a new job type resets all retention policy and legal hold values on the index, launchable from the tenant status page next to the purge job
- Saved searches: preset time filters (today, yesterday, and similar) are now supported in saved searches
- Global saved searches while impersonating: admins can now save searches as global while impersonating a user, and exports started from the UI respect impersonation
- Connector statistics: a historical badge marks users who are no longer being synced, as opposed to users still in the sync queue
- Log panel: a refresh button reloads log files without closing and reopening the panel
- Search on Enter: email search starts on <kbd>Enter</kbd> from any field in the search form
- Search term highlighting: terms matched by a full-text search are highlighted in the result list, message headers, and message body, following the same rules as the index (accent-insensitive, no stemming)
- Manticore installation check: a daily command checks that the indexing engine loaded all its libraries, and notifies you with the current CPU model if the CPU doesn’t support the instruction set the engine needs
Security
- Local admin password expiration: a configurable password expiration policy for local users, requiring a password change after the set period but still allowing login with an expired password until it’s updated. Users with an expired password are redirected to a forced password-change page before doing anything else, and the new password must be different from the current one
- Email-to-PDF rendering: the renderer could be tricked by attacker-created message HTML into reaching internal services, including the search index. It now runs in an isolated network namespace with no interface or route, so nothing it fetches can leave it
- Indexing engine: the HTTP-capable listener has been completely removed, and the remaining listener requires native authentication with a least-privilege application account
- Message folders: folder listing now checks the mail-viewing capability
- Uploads: a local privilege escalation via mail-ZIP upload followed by root-side extraction was fixed, and PST upload/import paths are now standardized and limited to an approved list of upload roots
- Export: a mailbox folder name with path traversal sequences could cause an export to write files outside its destination directory and overwrite other files on the appliance. Folder names are now sanitized before being used to build a path
- SSO login: reflected XSS fixed by rejecting unsafe schemes in redirect URLs
- SQL injection: index and table names are validated before being used in SQL, and a possible injection via string-based query concatenation was removed
- Connector logs: a connector user log was stored under the synced address only, so two tenants archiving the same address shared one file. Each sync would erase the other tenant’s log, and either operator could read what the other’s connector wrote. Logs are now kept per connector, and the connector is resolved server-side from the caller’s tenant
- Public API: unauthenticated endpoints (username and domain verification, OTP confirmation, add-in login, OAuth2 and token refresh) were unthrottled and not visible to intrusion prevention. They now have per-IP rate limits, a standard log line, and their own intrusion prevention jails, with an initial throttling layer in the web server. Normal use, like an expired session or a group signing in at once, is intentionally excluded from the jails
- User enumeration: username verification no longer works as an availability oracle
- Archives: now encrypted with AES-256 instead of the weak ZipCrypto method 7z uses by default. Reading existing archives is unaffected
- Outlook add-in: the manifest now requests read-item permission instead of read/write access to the whole mailbox, since the add-in never writes. Tenants who already deployed the add-in keep the old permission until the manifest is redeployed
- Content Security Policy: inline scripts and the jsdelivr CDN are no longer allowed, and framing and form submission are limited to the appliance itself. The SSO, SAML, and OAuth2 landing pages no longer run inline scripts, and the API documentation page now serves its assets locally instead of from the CDN
Improvements
- Folder-scoped searches, counts, and zip-name lookups now process folder IDs in chunks and combine the results, so searches and exports across very large sets of folders finish instead of failing
- Full-text ranking now uses per-field weights on the existing index, with no need to reindex or change the schema, so older emails benefit right away
- Office attachment text extraction now reads documents directly in-process instead of starting three separate shell processes for each attachment
- Volume retention jobs no longer trigger a file listing when there’s nothing to clean up
- Temporary backup files left behind by interrupted upload phases on volumes are now cleaned up every hour instead of during volume retention
- Automatic handling of failed appliance updates with user notifications, including better management of update timeouts and an apt lock timeout
- Export jobs are now more resilient during long-running operations, including automatic recovery if the connection to the indexing engine is temporarily lost
- PST tooling memory: the memory limit for PST tools is now based on the appliance’s physical RAM and applies to every operation, not just exports. Parallel extractions each get a share, and the read/write paths no longer leak memory. Exporting a large archive on a low-RAM appliance no longer grows into swap until the system kills the operation
- Folder move history: every time a message was moved between folders, the archive recorded the change, so messages moved back and forth for years could accumulate thousands of records—sometimes over a thousand per message. A nightly sweep now keeps only the current state and removes redundant history. Targeted and dry-run modes are available for support, and the sweep never runs on a passive cluster node
- Orphan chunk cleanup on the indexing engine now also removes normal chunks that the index no longer references, per table, and only when every file in a chunk group can be safely removed
- Volume upload failures now log the entire exception chain instead of just the outermost generic message, which helps identify storage-side errors
- Date filters were previously resolved using the appliance’s default time zone instead of the searching user’s, causing off-by-one results at day boundaries. Filters, saved searches, and the Outlook add-in now all use the user’s time zone
- Index optimization: the indexing engine now compacts its tables in the background automatically, replacing the two hourly optimization jobs. Its target is refreshed nightly based on index size. The "Latest index optimization" card has been removed from index statistics
- Indexing engine crashes: core dumps are now capped at 1GB, so if the engine crashes, it no longer spends minutes writing a dump as large as the engine’s memory before restarting
- Web interface in background tabs: a hidden tab no longer polls the appliance every few seconds; it stays signed in with one request every five minutes, and jobs and notifications refresh as soon as the tab is visible again
- Connector synchronization: a second copy of the connector output was previously buffered in a temporary file for the entire run, reaching several GB on large mailboxes; this is no longer kept
- IMAP folder synchronization: drafts and junk folders are now recognized by their standard IMAP special-use flag, not just by their English or Italian names, so localized folders like Entwürfe or Courrier indésirable are no longer archived
- SNMP: every Archiver OID now starts with the same standard prefix,
.1.3.6.1.4.1.41091.2, so a monitoring system can poll the entire Archiver tree from a single root. Eighteen OIDs covering license, listeners and connectors, finalizer, queue, database check, and indexing engine were previously published under a different prefix and are now also available under the standard one. The old OIDs will still respond so monitoring can switch over, but will be removed in 6.0
Bug fixes
- Export by folder could not finish for folders with more than 100,000 emails
- PST exports logged a "corrupted messages" error every time, counting the fixed recap lines the tool always prints instead of the actual number of failures
- Creating a volume from the export configuration redirected to the volumes page, causing the export being set up to be lost
- Office 365 SSO login failed with
AADSTS50076on tenants enforcing MFA - Connector folder synchronization failed on well-known folders and on Microsoft Graph mail folder responses
- Gmail messages with no labels, and Gmail message deletions seen through change fetching, interrupted synchronization
- S3 multipart uploads to AWS buckets with Object Lock failed due to missing part checksums,
InvalidPart, or unsigned headers - Large downloads through the volume browser could use up all temporary filesystem space; available space is now checked before starting the download
- The jobs list failed as soon as a job belonging to a hard-deleted tenant existed, so the jobs popup silently showed "No jobs to show" for every superadmin, on every page
- Reports failed for tenants whose names start or end with an apostrophe
- Japanese message bodies encoded in ISO-2022-JP were not decoded
- Editing attachment indexing changed the loaded configuration before it was saved
- Let's Encrypt certificate renewal now refreshes the system CA store and retries once if certbot can’t validate the ACME server’s TLS certificate
- A backup volume that was full could never be cleaned up, since retention only ran after the backup, which failed due to lack of space
- Microsoft 365 license count: users whose only Exchange plans were Bookings or Graph Connectors Search were counted even though they had no mailbox, while users with a subscription in its grace period were not counted at all
- A saved search shared with all users kept appearing in the list after being deleted
- Google SSO login failed with a server error once the access token expired; the token is now refreshed, or the user is prompted to sign in again
- The cluster setup check reported the snapshot disk as missing on NVMe appliances
- A log or backup volume that failed its upload repeatedly would crash instead of being disabled with a notification
- Removing /mnt/disk1 also removed the fstab entries for /mnt/disk10 to /mnt/disk19, which then weren’t mounted after a reboot, and refused to remove disk1 while disk10 held a volume. If the unmount failed, the removal would go on to delete the data from the disk that was still mounted
- The disk mount and cluster snapshot disk setup scripts partitioned the disk regardless of the answer to their confirmation prompt, and pressing <kbd>Enter</kbd> at the disk prompt selected the first disk
- Mounting a disk that had been removed earlier formatted its old partition and left a junk partition behind, and a failed mount left an fstab entry that caused the next boot to go into emergency mode
- Disk expansion could pick the wrong disk when /mnt/disk10 to /mnt/disk19 were also mounted, didn’t grow the filesystem because the kernel kept the old disk size, and always failed on unencrypted images like AWS
- On virtio appliances, the cluster scripts couldn’t find the snapshot disk: node initialization failed, synchronization reported the cluster as not set up, and setup would partition a second disk
Breaking changes
- The "Moved" metric has been removed from connector statistics and the connector report. It was never directly measured, only inferred from how often a message changed folders, and the cleanup described above makes that inference impossible: the column would have shown zero for every user, past and future
- Password-protected archives no longer open with the tools built into Windows. Archives are now encrypted with AES-256, and neither the "Compressed Folders" feature in Windows Explorer nor Info-ZIP unzip 6.00 can extract them. 7-Zip, WinZip, and WinRAR can open them as usual. Explorer only ever supported the old ZipCrypto encryption and never the WinZip AES standard, so this is a Windows limitation with no workaround on the appliance side
Deprecation notice
-
Legacy SNMP OIDs: the eighteen Archiver OIDs published under
.1.3.6.1.4.1.41091.1(license, listeners and connectors, finalizer, queue, database check, and indexing engine) are deprecated and will be removed in the next major release. Each one is already available under.1.3.6.1.4.1.41091.2with the same suffix, so.1.3.6.1.4.1.41091.1.4.1.0becomes.1.3.6.1.4.1.41091.2.4.1.0. Monitoring systems polling the old OIDs should switch to the new ones ahead of time
How to upgrade
To apply this update, go to Appliance > Administration > Version & updates where you can choose to install the new version right away or schedule the upgrade for the upcoming night.
Please note that after the update process finishes, the appliance will automatically reboot to make sure all changes are applied and services restart with the new version.