High-severity Nvidia DCGM Exporter bug exposed 2,100 GPU servers online
Lava researchers found about 2,100 GPU servers exposing Nvidia's DCGM Exporter metrics to the open internet without authentication, covering 12,000 GPU UUIDs at roughly 300 organizations. The high-severity flaw CVE-2026-47483 (CVSS 8.2) could let unauthenticated attackers crash the monitoring service and disrupt AI workloads; Nvidia fixed it in version 4.8.2.
- About 2,100 servers exposed DCGM Exporter metrics and 12,000 GPU UUIDs without authentication
- 44% of exposed GPUs are in the US, including Blackwell Ultra B300, H200 and H100
- CVE-2026-47483 carries a CVSS 8.2 rating; the fix shipped in version 4.8.2
- Researchers also found 12,096 publicly exposed Prometheus Node Exporter hosts
Read next
Security