Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2026-33701 is a critical severity vulnerability with a CVSS score of 9.8. No known exploits currently, and patches are available.
Lower probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. An attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability:
-javaagent)Arbitrary remote code execution with the privileges of the user running the instrumented JVM.
Upgrade to version 2.26.1 or later.
Set the following system property to disable the RMI integration:
-Dotel.instrumentation.rmi.enabled=false
This vulnerability was responsibly disclosed in coordination with Datadog.
| Vendor | Product |
|---|---|
| Linuxfoundation | Opentelemetry Instrumentation For Java |
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.