By Jessica Lyons
Publication Date: 2026-10-08 18:17:00
Researchers found thousands of GPU servers exposing Nvidia’s DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads.
DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP.
This exposure provides would-be attackers with detailed information useful for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity.
Michael Katchinskiy, a researcher at datacenter security startup Lava, found and reported the bug in the GPU health and performance monitoring service. In September, the GPU giant Nvidia released a fix for the flaw, tracked as CVE-2026-47483, and gave it an 8.2 CVSS high-severity rating.
“Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?” Katchinskiy said in a Thursday blog.
So the researchers started scanning the internet for exposed DCGM…


