Two advisories, two days apart, describe the same unnerving idea. On August 11 CISA published a warning about a vagus nerve stimulator that people wear on their neck. Today it published one about a headset that people strap to their forehead to treat depression at home. In both cases, according to CISA, somebody standing within Bluetooth range can talk to the device without a password and change the electrical stimulation it delivers.
Both were found by the same person. Each advisory credits the researcher A.C. Buglione, and nobody appears to have connected the two yet.
The headset
Today's advisory covers the Flow Neuroscience FL-100, listed under both the Flow Neuroscience and Halo Neuroscience product names. Flow is a Swedish company that sells the headset directly to people at home as a medication-free depression treatment. It works by transcranial direct current stimulation, or tDCS, passing a small current through the skull toward the part of the brain involved in regulating mood, and the whole thing is driven from a phone app.
The flaw, CVE-2026-18164, is an undocumented hard-coded credential, and CISA's wording repays a close read. The credential is "shared by all device units" and "is authorized to bypass authentication", which allows an attacker within Bluetooth range to "arbitrarily manipulate brain stimulation parameters and state". One secret, every unit that was ever shipped, no sign to the owner that it exists at all. CISA scores it 8.1 on CVSS v3.1 and 7.2 on v4.0. Versions before July 2026 are affected, and the good news is that Flow has shipped a firmware update through its app.
The neck band
The August 11 advisory covers the Pulsetto Vagus Nerve Stimulator, made by a Lithuanian company and sold for stress, sleep and anxiety in four-minute sessions. Its flaw, CVE-2026-18844, is filed under a weakness class you almost never see in the wild: hidden functionality. The firmware "accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface", CISA writes, and those commands "are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on". Using them, an attacker can "disable electrical safety mechanisms or modify other stimulation output settings". The scores are identical to the Flow bug, 8.1 and 7.2.
There is no patch. CISA states plainly that Pulsetto "has not responded to requests to work with CISA to mitigate this vulnerability", and tells owners to approach the company themselves. Every version of the device is affected.
What is, and is not, being claimed
This is the kind of story that invites exaggeration, so it is worth being exact. CISA says neither flaw is exploitable remotely, and reports no known public exploitation of either one. An attacker has to be physically near you, inside Bluetooth range. What CISA does say is that the safety limits, the ones that are supposed to bound how much current these things push into a person, can be overridden by somebody who is.
Why nobody is going to patch these
The uncomfortable part is not the bugs, it is the distribution model. These are not hospital machines with a biomedical engineering department and a patch window. Flow's headset arrives at your door. Pulsetto states that it is "a general wellness product and is not intended to diagnose, treat, cure, or prevent any disease", and CISA nonetheless files it under the Healthcare and Public Health sector, with both devices listed as deployed worldwide. The update path for a device like this runs through a consumer app that its owner may not have opened in months, and for Pulsetto owners there is currently nothing to install.
If you use either one, open the companion app and take the firmware update where one exists, and think of pairing as something you do at home rather than on a train. That is thin advice, which is rather the point.
CISA has now issued three advisories on consumer-grade health devices in three days. We covered the first of them, flaws in the Mira hormone monitor that exposed reproductive health data, reported by a separate team at Northeastern University's SPQR Lab. The thing worth watching is not any single bug. It is that one researcher has pulled apart two consumer neurostimulation wearables in three days and found both of them taking orders from strangers. There is no particular reason to believe those were the only two.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.