Blog Post

Fabric Updates Blog
2 MIN READ

On-premises data gateway May 2026 release

lrtoyou1223's avatar
lrtoyou1223
Icon for Microsoft Employee rankMicrosoft Employee
3 months ago

New Features

Admin consent for gateway diagnostics and enhanced Dataflow Gen2 diagnostics (Preview)

We’ve introduced Admin consent for gateway diagnostics, a feature that gives organizations explicit control over whether diagnostic data from on-premises data gateways is collected and sent to the cloud.

This capability follows a consent-driven model to ensure that potentially sensitive data, such as Mashup logs, is only transmitted after administrative approval. Gateway administrators can enable diagnostics at the gateway level, while tenant administrators retain organization-wide control and can revoke consent at any time. If consent is revoked, all gateways immediately stop sending diagnostic data and any ongoing transfers are terminated.

In addition, gateway diagnostics are now integrated directly into the Dataflow Gen2 run experience, addressing a common challenge where troubleshooting required switching across multiple tools and log sources. With this update, relevant gateway logs are surfaced alongside dataflow execution details, providing a unified, end-to-end view of execution. This enables faster root-cause analysis and helps users quickly determine whether issues originate from dataflow logic, gateway connectivity, authentication, or downstream systems.

Power BI Desktop compatibility

This update brings the on-premises data gateway up to date with the May 2026 release of Power BI Desktop.

Download on-premises data gateway (standard mode)

Download on-premises data gateway (personal mode)

This version of the gateway will ensure that the reports that you publish to the Power BI Service and refresh via the gateway will go through the same query execution logic/run-time as in May’s version of Power BI Desktop. View the data connectivity section of Power BI’s May 2026 feature summary for updates on relevant connectors.

Updated 3 months ago
Version 1.0

5 Comments

  • lrtoyou1223 FYI, it seems the Apache log4j library bundled with the On-premises Data Gateway (installed in FabricIntegrationRuntime\5.0\Gateway\Jars\log4j-core-2.25.3.jar) has a serious security vulnerability. SEE https://nvd.nist.gov/vuln/detail/CVE-2026-34480

    Can your team please investigate updating log4j to resolve this vulnerability in the next release? Thank you!

  • When I raised this issue via a support ticket in May, I was told that this vulnerable version would be replaced in the June release.

    So that would be out towards the end of June.

    In the meantime, the most sensible mitigation is probably to just delete the log4j jar files (From: C:\Program Files\On-premises data gateway\FabricIntegrationRuntime\5.0\Gateway\Jars\ ) as most integrations don't even really need/use this - SQL Server integrations don't anyway. (Depends on what sources you're connecting with.)

    It'd be nice if MS could just make a published statement to say there's no feasible way to exploit this anyway, due to the way the stuff is called. But in the meantime...you can just nuke the jar files to keep the Vuln scanners happy.

  • Question About Vulnerability Updates for Simba ODBC Drivers in On‑Premises Data Gateway (June 2026)

    I'm currently running On‑Premises Data Gateway v3000.322.4 (June 2026) and noticed several vulnerability findings related to the libcurll.dll libraries bundled with some of the ODBC drivers included in the gateway. Specifically:

    • Simba Google BigQuery ODBC Driver — affected by CVE‑2023‑38545 (C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurll.dll) v7.84.0.0
    • Simba DocumentDB ODBC Driver — affected by CVE‑2026‑6276
    • A few additional Simba‑based drivers also appear to reference outdated libcurl components.

    Before opening a support ticket, I wanted to check here first:

    Does anyone know when Microsoft plans to update these bundled ODBC drivers to versions that include patched libcurl libraries?

    Any insights, timelines, or references to upcoming gateway releases would be greatly appreciated.

    Thanks!