CISA Warns All Pulsetto Vagus Nerve Stimulators Have Unpatched Bluetooth Vulnerability That Could Allow Attackers to Disable Safety Mechanisms

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an official medical device security advisory warning that all versions of the Pulsetto Vagus Nerve Stimulator contain a significant cybersecurity vulnerability that could allow an attacker to disable the device’s electrical safety mechanisms or alter its stimulation output settings.
Hidden Bluetooth Commands Create a Security Risk
According to the official CISA announcement, released under alert code ICSMA-26-223-02, the vulnerability — tracked as CVE-2026-18844 — exists in the device’s firmware, which accepts hidden, undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are processed by the device without any authentication or encryption whenever the device is powered on. Critically, the commands are never sent by the device’s companion mobile application, meaning they represent a covert channel that operates entirely outside normal use.
CISA rated the vulnerability HIGH severity, with a base score of 8.1 under CVSS version 3.1, reflecting the potential for an attacker within Bluetooth range to significantly affect the integrity and availability of the device without needing any special credentials or user interaction.
The advisory states that every version of the Pulsetto Vagus Nerve Stimulator is affected. The device is manufactured by Pulsetto, a company headquartered in Lithuania, and is deployed worldwide. The healthcare and public health sector is identified as a critical infrastructure sector affected by this vulnerability.
Of particular concern noted in the CISA announcement is that Pulsetto has not responded to requests from CISA to work together on mitigating the vulnerability. As a result, no manufacturer-issued patch or firmware update is currently available. CISA is directing users to contact Pulsetto directly at info@pulsetto.tech for assistance.
What Pulsetto Users Can Do to Reduce Their Risk
In the absence of a fix, CISA recommends that users and healthcare organizations take defensive steps to reduce risk. These include minimizing Bluetooth and network exposure for the device, keeping it away from untrusted networks, and following general cybersecurity best practices for medical and control system devices. The agency notes that organizations observing suspected malicious activity related to this vulnerability should report it to CISA.
The vulnerability was reported to CISA by security researcher A.C. Buglione.
Vagus nerve stimulators are wearable medical devices used by consumers for stress management and wellness applications. Owners of any version of the Pulsetto device should be aware of this unresolved security issue.
Readers should verify the details of this advisory and any updates directly with CISA at cisa.gov or by contacting Pulsetto, as individual device circumstances may vary.
What to Read Next
6 Dashboard Warning Lights That Should Not Be Covered With Tape
PHMSA Confirms January 1, 2027 Effective Date for Updated Federal Pipeline Safety Standards






