Government Advisory

Security Flaw Found in Pulsetto Vagus Nerve Stimulator Device

CISA · 11 Aug 2026
Key Takeaway If your business uses any connected health, wellness, or IoT devices, keep track of manufacturer security advisories and apply updates promptly to avoid hidden vulnerabilities putting users at risk.

A security flaw has been identified in the Pulsetto Vagus Nerve Stimulator, a wellness device used worldwide and manufactured by Lithuania-based Pulsetto. According to an advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the vulnerability involves 'hidden functionality' that could allow an attacker to disable the device's electrical safety mechanisms or alter its stimulation output settings without the user's knowledge.

The flaw, tracked as CVE-2026-18844, has been given a CVSS severity score of 8.1, indicating a high level of risk. It affects all versions of the device and falls under the Healthcare and Public Health critical infrastructure sector, meaning it could have real-world safety implications for users relying on the device for health-related purposes.

While this device is a consumer wellness product rather than typical business IT equipment, the incident is a useful reminder for small businesses that any internet-connected or smart device—from medical wearables to office equipment—can carry hidden vulnerabilities. Businesses that supply, recommend, or use connected health and wellness devices for staff wellbeing programs should stay alert to manufacturer security advisories and updates.

IoT Security Medical Devices Vulnerability Advisory CISA Healthcare

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.