Cyber Resilience
← All news

Pulsetto Vagus Nerve Stimulator

Our takeCISA advisory ICSMA-26-223-02 flags CVE-2026-18844 in all versions of the Pulsetto Vagus Nerve Stimulator: hidden commands can disable safety mechanisms or alter output.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-18844 in the Pulsetto Vagus Nerve Stimulator; hidden commands can disable safety mechanisms or change stimulation output. If your organization uses these devices in clinical or research settings, isolate them from networks, apply any vendor mitigations immediately, and monitor for unauthorized configuration changes.
What this means for you — Lean IT orgs:CISA reports active exploitation of the Pulsetto Vagus Nerve Stimulator. If your clinic, wellness center or small practice uses one of these devices, disconnect it from any network or app until the vendor provides a fix.
What this means for you — MSP:CISA reports active exploitation of CVE-2026-18844 in Pulsetto Vagus Nerve Stimulators. Check every client site or telehealth provider that uses these devices; isolate them from networks and confirm the vendor supplies a patch or workaround.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-18844 in all versions of the Pulsetto Vagus Nerve Stimulator. Successful exploitation lets an attacker disable electrical safety mechanisms or alter stimulation output via hidden commands.