LIVE FEED
CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response CISA: every Flow Neuroscience FL-100 tDCS headset shares one hardcoded BLE credential, CVE-2026-18164 rated 8.1 Coalition for Health AI convenes 100 member cyber work group, AI attack and defense playbooks due by year end CRA Article 14 reporting obligations take effect September 11 EU MDR revision proposal adds a 30 day exploited-vulnerability reporting clock via Eudamed Mira hormone monitor cloud API handed session tokens to any password, CVE-2026-68067 rated 9.8 Pulsetto vagus nerve stimulator ships hidden BLE commands: no patch, no vendor response
Sunday, August 16, 2026 Issue #1  ·  Est. 2025
Independent brief for device makers
Section 02 // CVEs · Advisories · Exploits

Vulnerabilities

Flaws, advisories, and exploit activity across the connected medical device fleet.

Latest Filings

43 stories on file
01
Vulnerability

Flow Neuroscience FL-100 ships a shared Bluetooth credential in every unit

CISA advisory ICSMA-26-225-01: every Flow Neuroscience FL-100 shares one hardcoded credential, CVE-2026-18164, CVSS 8.1. An attacker in Bluetooth range can alter brain stimulation parameters. Firmware before July 2026 is affected; the fix ships through the Flow app.

CISA3 days ago2 min read
02
Vulnerability

Hidden BLE commands can switch off a vagus nerve stimulator’s safety limits

CVE-2026-18844 rates 8.1 on CVSS v3.1. The Pulsetto vagus nerve stimulator’s firmware accepts undocumented Bluetooth Low Energy commands with no authentication, letting anyone in range disable electrical safety mechanisms or change stimulation output. Every version is affected, CISA got no answer from the vendor, and no patch exists.

CISA5 days ago2 min read
03
Vulnerability

Mira’s cloud login accepted any password and returned a session token

ICSMA-26-223-01 lists eight CVEs in the Mira Hormone Monitor and its Android app. CVE-2026-68067 (9.8) let the cloud API hand a session token to anyone holding a user’s email address, and CVE-2026-67568 (9.1) shipped hard-coded credentials inside the APK. Fixed in iOS 3.5.18, Android 4.5.18, and firmware 01.07.01.53.

CISA5 days ago3 min read
04
Vulnerability

CISA spent the summer working through the DICOM stack

Four medical advisories this year hit GDCM, pydicom, OHIF and DCMTK. Not niche libraries. The imaging plumbing inside commercial products.

CISA6 days ago4 min read
05
Vulnerability

Philips’ July advisory run is a lesson in where device risk actually lives

A security vendor’s breach. A DICOM toolkit. A Windows kernel RCE. A Defender bypass. Four advisories in two months, none for a bug Philips wrote.

Philips Product Security6 days ago3 min read
06
Vulnerability

A crafted JPEG inside a DICOM file overflows a viewer heap

ICSMA-26-218-01: RadiAnt DICOM 2025.2 and earlier contain a heap overflow triggered by maliciously crafted JPEG pixel data in a DICOM file, a potential path to code execution. Update to 2026.1.

CISAAug 62 min read
07
Vulnerability

DNA analyzer output could be tampered with, and the software would not notice

ICSMA-26-216-01: data-collection software for Applied Biosystems genetic analyzers lacked integrity checking on its output files. A proof of concept merged two DNA profiles without tripping any warning.

CISAAug 43 min read
08
Vulnerability

CISA worked through the open-source DICOM stack all year

GDCM, pydicom, the OHIF viewer and OFFIS DCMTK all drew medical advisories in 2026. These libraries are the imaging plumbing inside commercial products, which means the advisories are really about your SBOM.

CISAJun 304 min read
09
Vulnerability

A bundled message broker shipped with guest:guest still enabled

Roche disclosed CVE-2026-9844 in navify Digital Pathology: the bundled RabbitMQ management interface shipped with default guest credentials unless changed, opening network access to messaging and management functions.

Roche DiagnosticsMay 292 min read
10
Vulnerability

Missing authentication lets an attacker rewrite a cardiac wearable

ICSMA-26-148-01: the Frontier X wearable ECG monitor and its apps allow reading and writing arbitrary handle values without authentication, CVSS 8.8, potentially altering clinical readings.

CISAMay 282 min read
11
Vulnerability

A hard-coded VNC password on a bioreactor, base score 9.8

ICSMA-26-146-01: the Eppendorf BioFlo 320 bioprocess controller ships a hard-coded password on its VNC remote-access interface, giving full control of the bioreactor to anyone who reaches it.

CISAMay 262 min read
12
Vulnerability

Compounding software that did not encrypt its database traffic by default

A Baxter bulletin flagged that Abacus supports encrypted client-server communication but did not enable transport encryption by default in legacy configurations, leaving SQL traffic open to interception.

Baxter Product SecurityMay 152 min read
13
Vulnerability

A security flaw in the server behind GE Revolution CT scanners

GE HealthCare recalled certain Revolution CT systems over a vulnerability in the AW Server deployed via its Edison Health Link subscription. About 200 systems worldwide, no breaches reported.

Radiology BusinessMay 112 min read
14
Vulnerability

Nine CVEs in Orthanc, and the image decoder is the soft spot

CERT/CC VU#536588: nine flaws in the Orthanc open-source DICOM server through 1.12.10, including heap overflows in the image decoder rated up to critical and decompression-bomb memory exhaustion.

CERT/CCApr 93 min read
15
Vulnerability

Login credentials exposed on the workstation in a GE imaging viewer

GE HealthCare issued an urgent correction for Centricity Universal Viewer after a flaw exposed user login credentials on the local client. An attacker with physical access could harvest them. FDA logged it as a Class 2 recall.

FDAMar 162 min read
16
Vulnerability

Stored passwords recoverable in a Siemens imaging platform

Siemens Healthineers SSA-016040: syngo.plaza VB30E stored passwords with weak encoding, letting an attacker recover the originals and gain unauthorized access. Fixed in VB30E_HF07.

Siemens HealthineersFeb 102 min read
17
Vulnerability

EMS patient-care app reflects unsanitized input into a WebView

ICSMA-26-041-01: the ZOLL ePCR iOS app reflected unsanitized field input into a WebView, opening script injection that could expose PHI captured in the field.

CISAFeb 102 min read
18
Vulnerability

A 9.8 in a power wheelchair: BLE takeover with no authentication

ICSMA-25-364-01: WHILL Model C2 and Model F powered chairs accepted Bluetooth control without authentication, CVSS 9.8. An attacker in range could stop or steer the chair.

CISADec 303 min read
19
Vulnerability

DLL hijack escalates a standard user to SYSTEM on dental imaging software

ICSMA-25-345-02: an uncontrolled search path in Varex/Panoramic dental imaging software lets a standard user escalate to SYSTEM through the ccsservice.exe component.

CISADec 112 min read
20
Vulnerability

User enumeration on the CareLink Network, found at a conference

Medtronic disclosed four flaws in the CareLink Network web layer, including observable-response user enumeration, after researchers probed a non-production instance at a security conference. Patched, no patient harm.

MedtronicDec 42 min read
21
Vulnerability

Hard-coded credentials and client-side auth in nuclear-medicine software

ICSMA-25-336-01: five high-severity flaws in Mirion Medical EC2 software (NMIS, BioDose), including hard-coded credentials and authentication enforced on the client.

CISADec 23 min read
22
Vulnerability

A hospital management backend leaked its own system information

ICSMA-25-301-01: Vertikal Systems Hospital Manager backend exposed sensitive system information to unauthorized users and returned error messages stuffed with more of it.

CISAOct 282 min read
23
Vulnerability

A null-pointer dereference can take down a central patient monitor

ICSMA-25-296-01: Nihon Kohden CNS-6201 central monitoring stations can be pushed into a denial of service, CVSS 7.5. The station is the screen that aggregates bedside vitals.

CISAOct 232 min read
24
Vulnerability

Missing authentication on a DNA sequencer control plane

ICSMA-25-294-01: the MinKNOW software that drives Oxford Nanopore sequencers shipped with missing authentication for a critical function, CVSS 8.6, plus weakly protected credentials.

CISAOct 213 min read
25
Vulnerability

A heart pump controller drew a Class I recall with no attacker in sight

Vulnerabilities in the Automated Impella Controller’s operating system could allow loss of device control or an unexpected pump stop. FDA classified the action Class I on potential harm alone.

MedTech DiveOct 143 min read
26
Vulnerability

A low-privilege user can walk past role limits in Synapse Mobility

ICSMA-25-233-01: FUJIFILM Synapse Mobility lets an authenticated low-privilege user manipulate a web search parameter to reach imaging and patient data beyond their assigned role.

CISAAug 213 min read
27
Vulnerability

Five flaws in Sante PACS Server, and one sends credentials in cleartext

ICSMA-25-224-01 covers five bugs in Santesoft Sante PACS Server before 4.2.3, including a double free that crashes the archive on a crafted HL7 message and a web portal that transmits credentials in the clear.

CISAAug 123 min read
28
Vulnerability

Empty passwords and cleartext storage in a home cardiac monitor

ICSMA-25-205-01: the Medtronic MyCareLink monitor stored data unencrypted, shipped a built-in account with an empty password, and deserialized untrusted data. Physical access required, no evidence of exploitation.

CISAJul 243 min read
29
Vulnerability

A dental imaging tool inherited a SYSTEM-level bug from an old SDK

ICSMA-25-198-01: Panoramic Digital Imaging Software was vulnerable to DLL hijacking inherited from an unsupported third-party SDK, letting a standard user escalate to SYSTEM.

CISAJul 172 min read
30
Vulnerability

Weak API input validation opens a monitoring platform to denial of service

Roche disclosed CVE-2025-7674 in navify Monitoring: an API lacked adequate input validation, so crafted or excessive data could be processed unsafely and knock the service over. Fixed before 1.08.00.

Roche DiagnosticsJul 172 min read
31
Vulnerability

MicroDicom patched, then patched again, for the same file-parser class

ICSMA-25-121-01 and ICSMA-25-160-01: MicroDicom DICOM Viewer took out-of-bounds write and read findings a month apart, both reachable by opening a crafted DICOM file, both around CVSS 8.8.

CISAJun 102 min read
32
Vulnerability

A legacy cardiology system, end-of-service since 2014, recalled for security

GE HealthCare recalled legacy MUSE cardiology systems after finding an outside party could view and manipulate stored patient data. About 4,200 systems, some out of service support since 2014.

Cardiovascular BusinessJun 103 min read
33
Vulnerability

Unrestricted file upload on a PACS points straight at code execution

ICSMA-25-100-01: INFINITT PACS System Manager had two unrestricted file-upload flaws toward remote code execution plus an information-exposure bug, on the server that holds the imaging archive.

CISAApr 102 min read
34
Vulnerability

A .NET Remoting port left wide open on an imaging workstation

Philips flagged deserialization of untrusted data in IntelliSpace Portal and Advanced Visualization Workspace: .NET Remoting on TCP 755 with TypeFilterLevel set to Full, a path to remote code execution.

Philips Product SecurityApr 103 min read
35
Vulnerability

Two rounds of memory-corruption bugs in one DICOM viewer

CISA hit Sante DICOM Viewer Pro twice in 2025: an out-of-bounds write (ICSMA-25-079-01) and later an out-of-bounds read (ICSMA-25-148-01), both triggered by opening a crafted file.

CISAMar 202 min read
36
Vulnerability

One AES key, shared across every install of a cardiovascular system

ICSMA-25-072-01: Philips IntelliSpace Cardiovascular built its auth tokens on a fixed AES-128 key identical across all installations, and let the login token be replayed to bypass authentication.

CISAMar 133 min read
37
Vulnerability

A DICOM viewer that did not check its update server certificate

ICSMA-25-051-01: RadiAnt DICOM Viewer failed to verify the update server TLS certificate, giving a man-in-the-middle attacker a path to deliver a malicious update.

CISAFeb 202 min read
38
Vulnerability

An open-source DICOM server that shipped with auth off by default

ICSMA-25-037-02: Orthanc Server before 1.5.8 did not enable authentication by default when the HTTP interface was exposed, leaving imaging records reachable to any unauthenticated attacker.

CISAFeb 63 min read
39
Vulnerability

A patient monitor with a hidden backdoor that phones home

ICSMA-25-030-01: the Contec CMS8000 monitor firmware beacons to a hard-coded IP and can pull and run files. CISA and FDA issued companion backdoor fact sheets, and the same firmware sits in relabeled monitors.

CISAJan 304 min read
40
Vulnerability

Default credentials across a line of diagnostic instruments

ICSMA-24-352-01: BD Diagnostic Solutions instruments including BACTEC and Phoenix shipped with default credentials, letting an attacker with network access read, modify or delete data including PHI.

CISADec 172 min read
41
Vulnerability

Unauthenticated SQL injection into an imaging database, base score 9.8

Siemens Healthineers SHSA-160244: syngo.plaza VB30E failed to sanitize input before the SQL server, letting an unauthenticated network attacker run arbitrary SQL and compromise the whole database.

Siemens HealthineersDec 63 min read
42
Vulnerability

Two maximum-severity flaws in a ventilation system

ICSMA-24-319-01: Baxter Life2000 Ventilation System carried nine CVEs, two rated a maximum 10.0, spanning hard-coded credentials, cleartext transmission, an exposed JTAG interface and missing authentication.

CISANov 143 min read
43
Vulnerability

A 10.0 SQL injection on a patient health portal

ICSMA-24-249-01: the Baxter Connex Health Portal had a critical unauthenticated SQL injection, base score 10.0, letting a remote attacker run arbitrary SQL, plus an access-control flaw exposing patient and clinician data.

CISASep 52 min read