Federal researchers have flagged serious security flaws in two popular consumer health devices, including vulnerabilities in a fertility tracker that could let attackers rewrite reproductive health records.
CISA’s advisory ICSMA-26-223-01, released August 11, covers eight vulnerabilities in the Mira Hormone Monitor and its Android app, the worst of which are critical. CVE-2026-68067 carries a 9.8 CVSS score and allows takeover of cloud accounts and access to hormone records, while CVE-2026-67568 at 9.1 permits read and write access to reproductive health profiles, enabling forgery or destruction of health information. Other issues include CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-66340, CVE-2026-64934, and CVE-2026-66832.
Researchers at Northeastern University’s SPQR Lab found the flaws during a full-chain review of the Mira Ultra 5 analyzer, its app, and cloud infrastructure, partly funded by an ARPA-H grant. They include weak authentication, hard-coded API keys, missing rate limiting, and publicly accessible firmware. Affected versions are firmware 1.7.1.47 and app 4.5.15.4. Maker Quanovate Tech is working on fixes.
Separately, CISA warned that the Pulsetto Vagus Nerve Stimulator accepts hidden commands over Bluetooth Low Energy with no encryption, tracked as CVE-2026-18844 at 8.1. Exploitation could disable electrical safety mechanisms or alter stimulation output. No patch exists, and CISA could not reach the vendor.
