The rapid growth of computing power for AI has left the security of some platforms far behind. In preparing the third version of the ClusterMAX study, in which SemiAnalysis evaluates the security, performance and reliability of cloud GPU clusters, experts checked 32 clusters from 25 providers and found errors that could disrupt customer isolation.
The inspection took place from April to July 2026 and covered networks, Kubernetes, storage, monitoring, and server management tools. In separate environments, BMC controller networks and IPMI interfaces were available to customers that allow you to manage hardware independently of the operating system. Some providers also did not share customer traffic through VLAN or VXLAN.
In InfiniBand networks, specialists found missing or incorrectly configured P_Key, M_Key and SA_Key keys. The first divides the devices into logical segments, while the rest limit the configuration change and access to service operations. Errors allowed you to see the metadata of neighboring customers and turn to the overall internal infrastructure.
On one of the clusters, outdated vCluster, publicly available kubelet and weak Kubernetes network policies have formed a chain of vulnerabilities. SemiAnalysis demonstrated the execution of the code between the two own tenants. The test did not affect other people's systems, and the provider then updated the platform and changed the configuration.
Another error revealed through Grafana and Prometheus magazines and indicators of all tenants. Among the available information were the names of the projects, the names of the subs of Kubernetes, the download of GPU and the data of the file systems. The infrastructure was attended by banks, telecom operators, universities, AI laboratories and the intelligence service of one of the largest economies in the world.
All verified providers received detailed notifications prior to publication. According to SemiAnalysis, no case went beyond the established 90-day period: the companies confirmed the installation of corrections or the specialists checked the result themselves. Operators were advised to isolate control networks, close BMC/IPMI, divide tenants, and ban Kubernetes traffic by default.
The inspection took place from April to July 2026 and covered networks, Kubernetes, storage, monitoring, and server management tools. In separate environments, BMC controller networks and IPMI interfaces were available to customers that allow you to manage hardware independently of the operating system. Some providers also did not share customer traffic through VLAN or VXLAN.
In InfiniBand networks, specialists found missing or incorrectly configured P_Key, M_Key and SA_Key keys. The first divides the devices into logical segments, while the rest limit the configuration change and access to service operations. Errors allowed you to see the metadata of neighboring customers and turn to the overall internal infrastructure.
On one of the clusters, outdated vCluster, publicly available kubelet and weak Kubernetes network policies have formed a chain of vulnerabilities. SemiAnalysis demonstrated the execution of the code between the two own tenants. The test did not affect other people's systems, and the provider then updated the platform and changed the configuration.
Another error revealed through Grafana and Prometheus magazines and indicators of all tenants. Among the available information were the names of the projects, the names of the subs of Kubernetes, the download of GPU and the data of the file systems. The infrastructure was attended by banks, telecom operators, universities, AI laboratories and the intelligence service of one of the largest economies in the world.
All verified providers received detailed notifications prior to publication. According to SemiAnalysis, no case went beyond the established 90-day period: the companies confirmed the installation of corrections or the specialists checked the result themselves. Operators were advised to isolate control networks, close BMC/IPMI, divide tenants, and ban Kubernetes traffic by default.