PatchSiren

Pulsetto CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Pulsetto CVE published 2026-08-11

CVE-2026-18844

The Pulsetto Vagus Nerve Stimulator's firmware accepts undisclosed commands over its Bluetooth Low Energy (BLE) interface without authentication or encryption. These commands are not issued by the companion mobile application but are fully processed by the device when powered on. This vulnerability has a CVSS score of 7.2 and is classified as HIGH severity.