Hello,
Tenable has identified multiple vulnerabilities regarding the On-premises Data Gateway like CVE-2026-8927, CVE-2026-9545, CVE-2026-9079, CVE-2026-49844, CVE-2026-8926, CVE-2026-8924 and more, most of them with critical or high severity in several libcurl.dll components.
The affected components currently contain the following versions:
- DocumentDB ODBC Driver – libcurl 8.12.1.0
- Simba Google BigQuery ODBC Driver – libcurl 7.84.0.0
- Simba DocumentDB ODBC Driver – libcurl 8.7.0.0
- Simba Hive ODBC Driver – libcurl 8.7.0.0
- Simba Impala ODBC Driver – libcurl 8.7.0.0
- Simba Spark ODBC Driver – libcurl 8.7.0.0
Our vulnerability scanner reports 8.21.0 as the fixed version.
Could you please confirm when Microsoft plans to release an updated On-premises Data Gateway version containing the patched libcurl components?
Thank you.