About 2,100 exposed DCGM Exporter hosts gave insight into data on 12,000 GPUs
The researchers behind the finding conducted four scans between March and May 2026 and identified roughly 2,100 publicly accessible NVIDIA DCGM Exporter hosts reporting more than 12,000 unique GPUs without authentication. At the same time, NVIDIA has patched a serious security flaw in the same tool that can crash GPU monitoring.
Two findings, one trap
What the security company Lava published on October 8, 2026 concerns two related but distinct problems in NVIDIA DCGM Exporter — a widely used tool for monitoring GPU clusters in data centers.
The first is exposure. Through four scans conducted between March and May 2026, Lava identified around 2,100 DCGM Exporter hosts that were publicly accessible on the internet without authentication. These endpoints reported more than 12,000 unique GPUs. The figures represent observations collected over the research period, not a live count of the current situation.
The second is a vulnerability. NVIDIA assigned it CVE-2026-47483, with a severity rating of 8.2 ("High"). The flaw lies in the tool's /debug/pprof endpoints, where concurrent, unauthenticated profiling requests can cause uncontrolled resource consumption — with potential denial of service and information leakage as a result. NVIDIA has released an update, and the company's security bulletin credits Lava's Michael Katchinskiy with the report.
It is important to keep the two findings apart: there is no indication that the observed organizations were actually exploited, or that all exposed GPUs were reachable through the vulnerable profiling interface. The exposure and the vulnerability are two distinct observations.
What kind of hardware was in the spotlight
Lava observed data-center accelerators of the H100, H200, and Blackwell Ultra B300 types, in addition to consumer- and pro-class RTX 4090 and 5090 systems. The company estimates that the observed GPUs represent more than $100 million in hardware, based on approximate market prices.
The estimate should be read with caution: it measures the value of the hardware, not losses. Nothing in the reporting suggests that anyone lost equipment, models, or data.
How much of the attack surface is actually vulnerable
Around a quarter of the exposed DCGM hosts also had internal Go profiling endpoints accessible. These are the endpoints that CVE-2026-47483 concerns. Lava reproduced the resource exhaustion in a controlled environment, using NVIDIA's official container — not by attacking public deployments.
The effect of crashing the exporter on neighboring workloads, such as training or inference jobs on the same machine, depends, according to the reporting, on resource isolation and how the system is deployed. So it is not established that a downed monitoring tool halts the GPU work itself, but neither is it ruled out.
What operators should do
For those running GPU clusters, the reporting points to three concrete checkpoints:
- Check whether DCGM Exporter is accessible from the internet without authentication.
- Upgrade to the patched version NVIDIA has released.
- Restrict access to the
/debug/pprofendpoints.
What remains open
Two questions remain. First: it is unclear what the exposure numbers look like today, since the scans ended in May 2026. Second: how much risk a downed monitoring tool actually poses to ongoing training or inference jobs depends on each individual deployment and is not generally established.
Otherwise, the finding peers at a layer of AI infrastructure that rarely gets attention — the monitoring tools that keep track of the GPUs, but which in thousands of cases were themselves openly available on the internet.

