CVE-2026-18844Disclosure

LOWCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Mentions · 2026-08-13: 1Active Exploitation · 2026-08-12: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 108-1108-1208-13
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-121
Active Exploitation1
2026-08-131
Disclosure1
Full discourse3 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 🩺 IoT Security · 11 August 2026 🎯 CISA flags Bluetooth security flaw affecting Pulsetto medical devices CISA has also issued an advisory covering CVE-2026-18844, a high-severity vulnerability affecting the Pulsetto Vagus Nerve Stimulator. The vulnerability involves undocumented functionality exposed through the device's Bluetooth interface. CISA warns that exploitation could interfere with electrical safety mechanisms or stimulation-output settings. The issue carries a CVSS v3 score of 8.1. 🔗 Source: CISA #Bluetooth #IoTSecurity #MedicalDevices #CVE #CyberSecurity

    Post summary

    CISA issues an advisory on CVE‑2026‑18844, a high‑severity Bluetooth flaw in Pulsetto Vagus Nerve Stimulators that could disrupt safety functions. No patch or exploit details are provided; the post primarily acts as a disclosure and warning.

    0000041
    53 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploited unprotected Bluetooth commands in the Pulsetto Vagus Nerve Stimulator to disable safety mechanisms and alter device settings. The vulnerability (CVE-2026-18844) accepts unauthenticated commands, enabling remote manipulation that could harm patients. #MedicalDevice #IoTSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/pulsetto-vagus-nerve-stimulator-cve-2026-18844

    Post summary

    This analysis confirms that CVE-2026-18844 allows unauthenticated remote manipulation via Bluetooth on Pulsetto Vagus Nerve Stimulators, and attackers have actively exploited it to disable safety mechanisms and alter device settings.

    0000057
    1.9K followersView on X
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ Pulsetto’s Bluetooth flaw affects every version—and there’s no firmware fix. A nearby attacker may alter stimulation settings, so your “wellness” gadget now needs a security perimeter. https://windowsforum.com/security-alerts.84/cve-2026-18844-pulsetto-ble-flaw-has-no-firmware-fix.442462/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #BluetoothSecurity #CisaAdvisory #Pulsetto #Cve202618844 https://t.co/WnAzDSjNKi

    Post summary

    Pulsetto’s Bluetooth flaw (CVE‑2026‑18844) affects all firmware versions, allowing nearby attackers to modify stimulation settings, but no patch or PoC is disclosed.

    0000040
    1.3K followersView on X

Explore more