CISA ICSMA-26-225-01: Bluetooth vulnerability in Flow FL-100 neurostimulator allows brain stimulation manipulation and safety-limit override
Executive summary
CISA published on August 13, 2026 advisory ICSMA-26-225-01 documenting CVE-2026-18164 in the Flow Neuroscience FL-100 transcranial direct current stimulation (tDCS) headset, an MDR Class IIa medical device indicated for home treatment of major depressive disorder (MDD). An attacker within Bluetooth range of the device can manipulate brain stimulation parameters and override the manufacturer’s safety limits, with direct clinical risk to the patient (excessive current, reversed polarity, extended sessions). CVSS v3.1 8.3 (HIGH) — vector AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H — confirms an adjacent-network (BLE), no-auth, no-user-interaction attack. Affected versions: Flow FL-100 and Halo Neuroscience FL-100 with firmware prior to July 2026. Patch is available distributed via the Flow app. Affected sector: IoMT — home-use medical devices for mental health, with potential impact on tens of thousands of outpatients in the U.S. and EU.
Key points
- Attack vector and surface: the device exposes a BLE interface without strong authentication (CVSS
AV:Aadjacent ≈ BLE ~10 m range,PR:Nno privileges required,UI:Nno user interaction). An attacker with a standard BLE sniffer (Ubertooth, nRF Connect, GATTacker) can pair or directly inject commands. - CVE-2026-18164 — parameter manipulation and safety-limit bypass: successful exploitation allows modification of stimulation current (typical device range 0.5–2 mA), session duration, electrode polarity, and, critically, overriding the safety clamps (current limits, session timeouts, interlock checks) that the manufacturer implemented as the clinical safety net.
- CVSS v3.1 8.3 (HIGH) — full vector
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H: confidentiality null (the device does not exfiltrate data), but integrity and availability HIGH — exactly the clinical-risk pattern where the device “appears to work” but delivers stimulation outside the prescription. CVSS v4.0AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:Nconfirms this. - Affected device and population: Flow FL-100 (CE Mark MDR Class IIa, marketed in the EU and UK for MDD) and Halo Neuroscience FL-100 (same hardware, rebranded for cognitive/athletic performance). Home use, not inpatient — patients are at home, often alone during their 20–30 minute session. Manufacturer-internal estimates indicate a five-figure installed base in Europe.
- Direct clinical risk: tDCS applies direct current through scalp electrodes over dorsolateral prefrontal / frontal cortices. Over-current (>2–4 mA), reversed polarity, or prolonged sessions can produce skin burns, severe headache, phosphenes, mania in undiagnosed bipolar patients, seizures in patients with unknown brain lesions, and sympathetic arousal with cardiovascular effects.
- Patch available but deployment opaque: Flow Neuroscience has shipped corrected firmware via the Flow app since July 2026. CISA has not added the CVE to the KEV Catalog (no confirmed public exploits), but the ease of BLE exploitation — no auth, no UI, adjacent — places the technical barrier at the minimum for any researcher or attacker with targeted clinical/extortion motivation.
- Not in KEV, but the vector is trivial: unlike CVEs that require chaining or phishing, this attack executes passively near the patient (café, public transit, office, attacker-known domicile). The device’s “perimeter” collapses to the patient’s BLE radius.
Regulatory implications
FDA (US)
Flow FL-100 does not currently hold a 510(k) or De Novo authorization for depression in the U.S. — its U.S. market presence is mainly as a wellness/research device. However, if reclassified or if device variants enter the regulated market, the advisory directly feeds the §524B FD&C Act file (cyber device monitoring and coordinated vulnerability disclosure) and would obligate the manufacturer to deliver threat model, SBOM, and post-market patch plan. The advisory sets precedent for FDA to apply the principle of “vulnerability should be designed out” when a Class II/III device exposes an inadequately authenticated wireless interface.
MDR (EU)
Flow Neuroscience operates in the EU under MDR (Class IIa). The advisory triggers post-market surveillance obligations (Art. 84–86 MDR) and, given the nature of the flaw (manipulation of therapeutic parameters), requires:
- FSCA (Field Safety Corrective Action) formal filing if the manufacturer notifies users — distribution of firmware via app is equivalent to a patch requiring user and competent authority notification per MDCG 2019-16 rev 1.
- Serious incident notification (Art. 87 MDR, ≤15 days) to the competent authority of the manufacturer’s home country and to the HSC (Health Security Committee) if affecting more than one Member State.
- PSUR update (Periodic Safety Update Report) with the new vulnerability and applied patch.
GDPR
The device processes mental-health data (Flow app records treatment adherence, mood, sessions) — these are special-category data under Art. 9 GDPR. A Bluetooth vulnerability that allows device manipulation but does not necessarily exfiltrate data does not directly trigger Art. 33 (breach notification), but if exploitation enabled access to companion-app data (optional heart rate, usage logs), the manufacturer would have 72 hours to notify the supervisory authority. Cloud platforms and mobile apps that extend the device are explicitly in scope of the new MDR cybersecurity framework.
NIS2 / ENS
Essential health operators (hospitals with mental-health clinics, telemedicine systems that prescribe the device) are essential entities under NIS2 (Annex I, health sector) and must comply with Art. 21 (risk management measures). The advisory requires:
- IoMT device inventory in use by outpatients (challenge: devices in the home, not in the hospital perimeter).
- Patient notification procedure if they are part of the clinical process.
- ENS HIGH in Spain: measures
[op.cont.4](incident management),[op.exp.5](vulnerability), and[op.mon.1](monitoring) apply when the device connects to corporate networks or is monitored remotely.
HIPAA
If the prescription originates from a HIPAA-covered entity and the device processes PHI (depression, concomitant medication, suicidality screenings), the device failure impacts the covered entity’s §164.308(a)(1)(ii)(A) risk analysis. The technical vulnerability itself is not a HIPAA violation, but not patching a prescribed device when the manufacturer has shipped a patch could be considered a failure of §164.308(a)(8) evaluation.
Recommendation
Immediate actions within the next 72 hours: (1) Inventory all Flow FL-100 and Halo FL-100 devices in use by depressed patients under own or partner-telemedicine prescriptions (cross-check prescription logs and device registration in the companion app); (2) Verify firmware version — devices with firmware prior to July 2026 are vulnerable; open a ticket with Flow Neuroscience if the Flow app does not auto-detect the update; (3) Notify patients with vulnerable devices via secure channel (Flow in-app message, encrypted email, clinical call) about the update and the symptoms of over-stimulation (persistent headache, phosphenes, electrode burning, paradoxical sedation/activation) — do not suspend use without clinical alternative; (4) Suspend new prescriptions of the device until fleet firmware is confirmed updated, especially in patients with neurological comorbidity or undiagnosed bipolar disorder; (5) Coordinate with liaison psychiatry so that any unexpected adverse event during a session is evaluated as a possible device safety event, not just clinical variability; (6) Review clinical integration of the FL-100 with the EHR — the session logs in the Flow app must be reconciled with the patient’s clinical record to detect out-of-range parameters; (7) Document the incident internally as input to the PSUR and to the §164.308 risk analysis if HIPAA applies, and prepare a draft notification to the MDR competent authority under Art. 87 if the manufacturer has not yet done so publicly; (8) Reinforce communication with the manufacturer requiring written confirmation of patch rollout, registry of un-updated patients, and a market-withdrawal plan if the installed base resists OTA update — an implantable, safety-critical device at home without a mandatory update channel is a §524B(b) (post-market monitoring) failure.
Source: CISA ICSMA-26-225-01 — Flow Neuroscience FL-100
This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.