High-severity flaws in Datadog dd-trace-java and OpenTelemetry Java Instrumentation can allow remote code execution through unsafe deserialization in their RMI instrumentation. The issues, tracked as CVE-2026-33728 and CVE-2026-33701, affect dd-trace-java versions 0.40.0 through before 1.60.2 and OpenTelemetry versions before 2.26.1. In both cases, the Java agent registers a custom endpoint that deserializes incoming data without serialization filters, creating an attack path on JDK 16 and earlier when a reachable JMX or RMI port is exposed and a compatible gadget-chain library is present on the classpath.
Successful exploitation would let an attacker execute arbitrary code with the privileges of the JVM process, but only when the agent is attached, the JMX/RMI service is explicitly configured and network-accessible, and the target environment contains a usable gadget chain. Datadog recommends upgrading to 1.60.3 or later, while OpenTelemetry users should upgrade to 2.26.1 or later; both vendors note that JDK 17 and later are not affected in the same way. For older Java deployments where immediate patching is not possible, disabling RMI instrumentation is the primary workaround, including OpenTelemetry's setting:
-Dotel.instrumentation.rmi.enabled=false

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic published security advisory ESA-2026-22 / GHSA-xw7x-h9fj-p2c7 for Elastic OTel Java 1.10.0. This represents a new vendor-specific disclosure and update related to the Java OTel instrumentation deserialization issue.
Datadog disclosed CVE-2026-33728 affecting dd-trace-java versions 0.40.0 through before 1.60.2, caused by unsafe deserialization in RMI instrumentation that could enable remote code execution on JDK 16 and earlier under specific exposure conditions. Datadog advised upgrading to dd-trace-java 1.60.3 or later, noted JDK 17+ does not require action, and suggested disabling the RMI integration as a workaround for older JDKs.
OpenTelemetry disclosed CVE-2026-33701 affecting Java Instrumentation versions prior to 2.26.1, where unsafe deserialization in RMI instrumentation could allow remote code execution on Java 16 and earlier if a reachable JMX/RMI port and a gadget-chain library were present. The project recommended upgrading to 2.26.1 or later and provided a workaround to disable RMI instrumentation on older JDKs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
discuss.elastic.co
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.