Multiple Critical Vulnerabilities Discovered in Mira Hormone Monitor and Android App
Quanovate Tech Inc. devices affected by authentication bypass, hard-coded credentials, and BLE security flaws
Key Takeaways
- Eight CVEs disclosed affecting Mira Hormone Monitor firmware and Mira Android App, with CVSS scores ranging from 6.5 to 9.8.
- The most critical flaw (CVE-2026-66875, CVSS 9.8) enables remote device rebinding, cleartext data extraction, denial-of-service, and user tracking via static BLE addresses.
- Attackers within BLE range (10–30 meters) can exploit the vulnerabilities without authentication to access health data, inject forged measurements, and compromise user accounts.
- Quanovate Tech Inc. recommends updating the Mira app to the latest iOS or Android version and allowing firmware v01.07.01.53 to update via the connected app.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


