CVE-2026-18844: Pulsetto Vagus Nerve Stimulator
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Affected products
- Pulsetto Vagus Nerve Stimulator: any version
Published 2026-08-11. Last modified 2026-09-08.