HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical BLE Command Injection Vulnerability (CVE‑2026‑18844) in Pulsetto Vagus Nerve Stimulator

A high‑severity BLE command‑injection flaw (CVE‑2026‑18844) allows unauthenticated attackers to disable safety mechanisms on Pulsetto Vagus Nerve Stimulators. For compliance teams, the issue underscores the need to map this control gap to SOC 2 criteria and collect continuous monitoring evidence.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

Critical BLE Command Injection Vulnerability (CVE‑2026‑18844) in Pulsetto Vagus Nerve Stimulator

What It Is — The Pulsetto Vagus Nerve Stimulator firmware accepts a set of undocumented Bluetooth Low Energy (BLE) commands that are processed without authentication or encryption. An attacker who can pair with the device can issue hidden commands to disable electrical safety mechanisms or alter stimulation parameters.

Exploitability — The vulnerability is rated CVSS v3.1 8.1 (High). No public exploit code has been released, but the attack requires only proximity to the device and a BLE‑capable tool, making exploitation feasible in many clinical environments.

Affected Products — Pulsetto Vagus Nerve Stimulator (all firmware versions).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The flaw highlights a gap in logical access and change‑management controls (SOC 2 CC6.1, CC6.2). Mapping this to your control inventory is essential for a defensible audit trail.
  • Continuous Evidence: Demonstrating ongoing monitoring of BLE traffic and firmware integrity provides the continuous‑compliance evidence that auditors now expect from medical‑device manufacturers.

Recommended Actions

  • Inventory all deployed Pulsetto stimulators and record firmware versions.
  • Segmentation – isolate BLE interfaces on a dedicated, monitored network segment.
  • Monitoring – deploy BLE traffic logging and anomaly detection to capture unauthorized command attempts.
  • Control Mapping – map the BLE authentication gap to SOC 2 access‑control criteria and capture remediation evidence.
  • Vendor Engagement – contact Pulsetto (info@pulsetto.tech) for any forthcoming firmware patches and document the outreach as part of your vendor‑risk process.

Source: CISA Advisory – ICSMA‑26‑223‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-223-02

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →