Critical Hard-Coded Credential Vulnerability in Flow Neuroscience FL-100 Brain Stimulation Devices
CVE-2026-18164 allows Bluetooth-range attackers to bypass authentication and manipulate stimulation parameters
Key Takeaways
- CVE-2026-18164 affects Flow Neuroscience FL-100 and Halo Neuroscience FL-100 brain stimulation devices with firmware before July 2026.
- An undocumented hard-coded credential shared across all units allows Bluetooth-range attackers to bypass authentication.
- Successful exploitation could enable manipulation of brain stimulation parameters and override of safety limits, posing health risks.
- CVSS v3 base score is 8.1 (HIGH); no public exploitation has been reported to CISA as of the advisory date.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


