Published Oct 9, 2026, 9:17 AM EDT Sanket Mungase is a freelance tech writer focused on the latest tech, Android, and Windows updates. When he is not writing, you can find him digging into interesting details about cars. Sign in to your How-To Geek account We’re used to hearing about GPUs overheating or power connectors melting. But this time, the threat comes from software that monitors NVIDIA’s GPUs and could have allowed attackers to disrupt vulnerable servers. Researchers at security firm Lava uncovered a high-severity vulnerability in NVIDIA’s DCGM Exporter. Tracked as ‘CVE-2026-47483’, and it has a CVSS score of 8.2 out of 10, for which a fix has been released by NVIDIA. What is NVIDIA DCGM Exporter? What does it do? DCGM Exporter is a monitoring tool that maintains and monitors the health of NVIDIA GPUs. This open-source tool collects GPU data such as temperature, memory usage, power consumption, performance, and errors. Tools like Prometheus read this information and send it to administrators to monitor their systems. Think of it as a health monitor for a GPU server. The main concern arises when this level of information is available publicly without authorized access. What is the vulnerability? How does it work? According to Michael Katchinskiy from Lava, “About a quarter of the exposed DCGM hosts in our scan were serving Go’s /debug/pprof/ profiling endpoints alongside /metrics.” This means the DCGM Exporter tool accidentally exposed a debugging feature called pprof, which shows how much memory and processing power a program is using. An unauthenticated attacker could send multiple requests to these hidden profiling endpoints, forcing the server to consume enormous memory and CPU power, resulting in a Denial of Service(DoS) attack, thereby crashing the monitoring tool, blinding operators to GPU health and activity, and dragging down AI work running on the same machine. It affected several systems What do the numbers say? “The exposed systems included NVIDIA Blackwell Ultra B300 GPUs, H200s and H100s used for large-scale AI workloads, as well as consumer RTX 5090 and 4090 systems,” Michael said. During the four scans between March and May 2026, the researchers found that data from about 2,100 GPU servers was available publicly, without any login. Together, those systems revealed information about more than 12,000 individual GPUs, representing an estimated $100 million in hardware. The report also mentioned that consumer GPUs and mining farms accounted for around 35% of the exposed systems, showing that the problem wasn't limited to large AI data centers. On a regional basis, the United States had the biggest share, accounting for 5,274 GPUs, or about 44% of all the GPUs identified in the scans. NVIDIA has addressed the issue A fixed version was released NVIDIA has addressed the vulnerability, and administrators are advised to upgrade DCGM Exporter to version 4.8.2 or later. It is also recommended to restrict access to authorized monitoring systems only and keep monitoring tools on private networks, protected by firewalls. With GPU prices soaring amid the ongoing AI boom, securing these valuable systems is more important than ever.
This NVIDIA security flaw could let attackers crash GPU monitoring services
Full Article
Original Source
Read the full article at Howtogeek →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.