CVE-2026-18844
Last modified
CVE-2026-18844 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Pulsetto | Vagus Nerve Stimulator | All |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18844?
How severe is CVE-2026-18844?
How do I fix CVE-2026-18844?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18835IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.9
- CVE-2026-18839An integer underflow was found in the popt library when form…2.2
- CVE-2026-1884A weakness has been identified in ZenTao up to 21.7.6-85642.…4.9
- CVE-2026-18840IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …7.8
- CVE-2026-18842IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …7.8
- CVE-2026-18843The Beaver Builder Plugin (Starter Version) plugin for WordP…6.1
- CVE-2026-18846IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overfl…7.5
- CVE-2026-18847IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenti…9.8
- CVE-2026-18848IBM Power Systems Firmware FW1120.00, FW1110.00 through FW11…8.3
- CVE-2026-18849IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vul…6.8
- CVE-2026-1885The Slideshow Wp plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-18851Missing authorization in Ivanti Endpoint Manager Mobile befo…8.8
Are you affected by CVE-2026-18844?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
