Hyperscalers are more likely to want to get OCP equipment or something similar; which might end up being something they bid out to supermicro, but it won't look like the retail servers. As spamizbad notes, the BMC/IPMI firmware is an issue too; it's mitigatable, but something that can run software the owner controls is much preferred (OpenBMC looks nice), if you have the scale to demand it.
This stuff is less of a problem if you're just using a few dozen of these things at most. But at scale commodity hardware becomes a nightmare.
It's why most hyperscalers find it more cost-effective to just build their own (Amazon, Google, Meta, others)
That's not a Supermicro-specific problem, though. In fact, the Oxide Computers folks are predicting their whole business approach on being able to "control and support" most every piece of firmware that they ship to users. It's not easy, and it's far from standard in the industry.
And by "hyperscalar" I mean "the ODM who actually designed the system".
Both Microsoft and Meta née Facebook hyperscaled their data centers using the AST1050.
All of the various Open Cloudserver specs call for BMCs: https://www.opencompute.org/wiki/Server/SpecsAndDesigns-old
Things haven't changed that much from these specifications.
(edit: link-to-highlight only works in Chromium-based browsers. everybody else, use Ctrl+F)
I reported a security issue about their BMC / IPMI to Supermicro, and Supermicro decided it wasn't a security issue, so they weren't going to do a thing.
There's no place in this world for companies that choose to wait for active exploitation before doing something.