CVE-2026-33728 is a critical remote code execution (RCE) vulnerability impacting Datadog's dd-trace-java library, specifically versions 0.40.0 through prior to 1.60.2. This CWE-502 flaw allows an unauthenticated attacker with network access to a JMX or RMI port to execute arbitrary code on instrumented JVMs running JDK 16 or earlier, due to unsafe deserialization without proper filters. With a CVSS score of 9.3 Critical, the vulnerability presents a low-complexity, network-based attack vector with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the issue has garnered community discussion highlighting the severe implications of RCE in monitoring tools. Exploitation requires dd-trace-java as a Java agent, an exposed JMX/RMI port, and a gadget-chain-compatible library on the classpath.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.40.0, < 1.60.3CPE matchmatch criteria | cpe:2.3:a:datadog:dd-trace-java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.