Executive summary

CISA has issued medical advisory ICSMA-26-223-02 warning of an unpatched vulnerability in all models of the Pulsetto vagus nerve stimulator (CVE-2026-18844). The device firmware accepts undocumented hidden commands over its Bluetooth Low Energy (BLE) interface that allow an attacker to disable the electrical safety mechanisms or modify the stimulation output settings. Pulsetto has not responded to CISA’s attempts to coordinate a mitigation, so no official fix exists. The advisory is directed at healthcare professionals and at users employing Pulsetto as complementary therapy for anxiety, insomnia and stress. CVSS v3.1 base: AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H (adjacent vector, low complexity, no privileges or interaction required; integrity and availability impact high). CVSS v4.0 also preserves VI:H/VA:H. Critical Infrastructure Sector: Healthcare and Public Health.

Key points

  • Vector: any device within BLE range of the Pulsetto (~10 m indoors) can emit hidden command sequences accepted by the firmware without authentication or visible pairing. No documented separation between legitimate and attacker-reachable command channels is known.
  • Patient impact: disabling the electrical safety mechanisms enables stimulation current to exceed safe clinical thresholds, with risk of bradycardia, arrhythmias, chest pain, local tissue burn, and — for users with pacemakers or implantable cardioverter-defibrillators (ICDs) — interference with cardiac therapy.
  • No patch, no vendor response: the Mitigation section of the CISA advisory explicitly states “Pulsetto has not responded to requests to work with CISA to mitigate this vulnerability”. Users have no official remediation.
  • Affected product: all versions (vers:all/*). The advisory does not distinguish models, firmware or regional variants.
  • Mitigation available only on the user side: disable BLE on the phone when not actively delivering therapy, keep the Pulsetto out of third-party BLE range, do not pair the device in public spaces, and consider discontinuing use until Pulsetto publishes signed firmware.

Regulatory implications

FDA (US)

Pulsetto is a US Class II medical device (transcutaneous vagus nerve stimulator, product code PZM). Under Section 524B of the FD&C Act and the FDA’s final cybersecurity guidance for medical devices (2023), the manufacturer is required to monitor, identify, and mitigate post-market vulnerabilities. The absence of a patch and non-response to CISA activates active post-market surveillance by the FDA and potential recall or safety communication actions. Healthcare professionals who recommend Pulsetto must inform patients of the ICSMA-26-223-02 advisory and document an individual benefit-risk assessment (FDA Guidance “Cybersecurity in Medical Devices: Quality System Considerations”, 2023).

MDR (EU)

Under Regulation (EU) 2017/745 (MDR), Pulsetto requires CE marking as an active medical device. MDCG 2019-16 rev 1 obliges the manufacturer to notify serious incidents and exploitable vulnerabilities to the competent authority of the Member State within ≤15 days (Art. 87 MDR). A vulnerability that allows stimulation parameters to be modified without user consent constitutes a serious incident if it could lead to clinical harm, and an unacceptable risk for which the manufacturer must issue a Field Safety Corrective Action (FSCA) — equivalent to a recall. If Pulsetto does not operate under a PRRC (Person Responsible for Regulatory Compliance) executing the FSCA, national authorities (AEMPS in Spain, MHRA in the UK, BfArM in Germany) must coordinate actions.

NIS2 (EU) and ENS (Spain)

For hospitals that dispense Pulsetto or any Pulsetto device, the vulnerability is a critical element of the supply chain risk analysis (Art. 21 NIS2, ENS HIGH [op.cont.4]). The medical device inventory must explicitly tag active Pulsetto devices with the open advisory and register them in the SOC for threat hunting of any anomalous BLE traffic in proximity of pacemaker/ICD patient areas.

HIPAA

If Pulsetto captures usage metrics (sessions, intensity, associated heart rate) that sync with companion apps on the patient’s phone, those data may constitute PHI under HIPAA’s definition (health data linked to an identifiable individual). A compromise of Pulsetto or its companion app requires notification assessment under §164.404.

Recommendation

Immediate actions within the next 72 hours: (1) Inventory every Pulsetto in use (patients, professionals, clinical research); (2) Formally notify Pulsetto ([email protected]) and the notifying body / competent authority of each user’s country, demanding a signed remediation plan and schedule; (3) Advise patients: suspend use unless clinical benefit is clearly documented and professionally supervised; (4) Disable BLE on the phone when not actively delivering therapy and keep the Pulsetto physically isolated from other BLE devices; (5) Threat hunt in proximity of clinical areas with pacemakers/ICDs: log any unknown BLE device interacting with Pulsetto; (6) Coordinate with cardiology service: if any user carries both Pulsetto and ICD/pacemaker, evaluate ICD telemetry for interference; (7) Clinical documentation: note in the chart that the patient uses a device with an open ICSMA-26-223-02 vulnerability; (8) FSCA / recall plan: prepare a controlled device withdrawal if Pulsetto does not publish signed firmware within a reasonable timeframe (≤30 days).


Source: CISA ICSMA-26-223-02 — Pulsetto Vagus Nerve Stimulator

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.