CVE-2026-33728Disclosure(datadog / dd-trace-java)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, dd-trace-java is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, a JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable, Third, a gadget-chain-compatible library is present on the classpath. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK >= 8u121 < JDK 17, upgrade to dd-trace-java version 1.60.3 or later. For JDK < 8u121 and earlier where serialization filters are not available, apply the workaround. The workaround is to set the following environment variable to disable the RMI integration: `DD_INTEGRATION_RMI_ENABLED=false`.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dd-trace-java

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
dd-trace-java

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 103-2703-28
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure3
2026-03-281
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Unsafe deserialization in `dd-trace-java` RMI instrumentation (CVE-2026-33728) could lead to RCE. Assess your `Java` applications using `dd-trace-java` for exposure. #Java #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-33728-dd-trace-java-rmi-deserialization

    Post summary

    The tweet announces CVE‑2026‑33728, highlighting unsafe deserialization in dd‑trace‑java RMI that can enable remote code execution, and urges users to check their Java applications.

    0000025
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33728 dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that… https://www.cve.org/CVERecord?id=CVE-2026-33728

    Post summary

    A vulnerability affecting dd-trace-java’s RMI instrumentation (CVE-2026-33728) has been disclosed, impacting versions 0.40.0 through before 1.60.2 due to a custom endpoint registration.

    00000102
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33728 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33728 #CVE-2026-33728 #CVE #Critical #CyberSecurity #InfoSec https://t.co/T9YhcC2Dzp

    Post summary

    The tweet alerts to the newly disclosed CVE‑2026‑33728, notes its critical severity, and links to NVD, but contains no technical specifics, PoC, or exploit details.

    0000031
    123 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33728: dd-trace-java: Unsafe deserializ... Datadog's RMI endpoint deserializes untrusted data without filters—classic gadget chain RCE waiting to happen on expose... https://zerodaysignal.com/vulnerability/CVE-2026-33728 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The snippet reports the existence of CVE‑2026‑33728 for Datadog's dd‑trace‑java RMI endpoint, highlighting unsafe deserialization that could lead to remote code execution.

    0000069
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdatadogdd-trace-java---

Explore more