Thousands of GPU servers have been found exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could allow unauthenticated attackers to crash the GPU monitoring service and disrupt AI workloads, according to a recent report by The Register.
Researchers discovered approximately 2,100 GPU servers with exposed DCGM Exporter metrics, including 12,000 GPU UUIDs, accessible without authentication. These servers belonged to around 300 organizations, with nearly half located in the U.S., representing an estimated $100 million in hardware. The vulnerability, tracked as CVE-2026-47483, allows attackers to crash the monitoring service by overwhelming it with unauthenticated requests, potentially impacting AI training and inference workloads. Nvidia released a fix in version 4.8.2. Additionally, 12,096 public Node Exporter hosts were found exposing server hardware and OS details, useful for reconnaissance. These exposures affected cloud providers like Nebius, Voltage Park, and Lambda. Security experts recommend restricting access to these monitoring services to authorized infrastructure to prevent such vulnerabilities.
Source: The Register
