Pulsetto Vagus Nerve Stimulator
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus Nerve Stimulator are affected: Pulsetto Vagus Nerve Stimulator vers:all/* (CVE-2026-18844) CVSS Vendor Equipment Vulnerabilities v3 8.1 Pulsetto Pulsetto Vagus Nerve Stimulator Hidden Functionality Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Lithuania Vulnerabilities Expand All + CVE-2026-18844 The firmware of the affected product accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on. View CVE Details Affected Products Pulsetto Vagus Nerve Stimulator Vendor: Pulsetto Product Version: Pulsetto Pulsetto Vagus Nerve Stimulator: vers:all/* Product Status: known_affected Remediations Mitigation Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability. Users are encouraged to reach out directly to Pulsetto for assistance at [email protected]. mailto:[email protected] Relevant CWE: CWE-912 Hidden Functionality Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments A.C. Buglione reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for a
CSIRTS triage
- What
- The device firmware accepts undisclosed commands over Bluetooth Low Energy without authentication or encryption, allowing attackers to disable electrical safety mechanisms or modify stimulation output.
- Who is affected
- All deployed versions of Pulsetto Vagus Nerve Stimulator worldwide, primarily affecting healthcare deployments.
- Urgency
- Critical urgency; the vulnerability affects medical device safety mechanisms and could cause direct harm to users.
- Action
- Contact Pulsetto for firmware updates that add authentication and encryption to the BLE interface, or discontinue use until patched.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Pulsetto Vagus Nerve Stimulator
Get an email when a new Pulsetto Vagus Nerve Stimulator advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-188440.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18844 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Pulsetto Vagus Nerve
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- highCISA Adds Three Known Exploited Vulnerabilities to Catalog2026-09-11
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-09-11
- criticalST Engineering iDirect iQ-Series Terminals (Update A)2026-09-10
- criticalOrthanc DICOM Server2026-09-10
- criticalCISA Adds Two Known Exploited Vulnerabilities to Catalog2026-09-10