
Unsafe RMI deserialization in dd-trace-java enables potential RCE
CVE-2026-33728 discloses critical unsafe RMI deserialization in Datadog’s `dd-trace-java` agent, risking JMX/RMI-port remote code execution on JDK 16 and earlier.
NewsJavaInsecure Deserialization
2 minToday

