CISA has published a high-severity advisory for the Mira Hormone Monitor and Mira’s Android app, warning that eight vulnerabilities could expose intimate health-profile data, enable unauthorized changes to account information, reveal session tokens, disrupt service, or lead to account takeover. The advisory, issued August 11, identifies Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4 as affected and assigns the vendor equipment vulnerabilities a CVSS v3 score of 9.8 out of 10.

For Mira users, the immediate problem is not merely the seriousness of the flaws. It is that the public advisory does not name a patched firmware release, a fixed Android build, a rollout date, or a reliable method for an owner to tell whether their monitor and app have received a security update. That leaves a consumer health device with a critical advisory but no clear public remediation path.

CISA says it has no reports of public exploitation specifically targeting these bugs. That is useful context, but it should not be read as evidence that the exposure is harmless: the listed weakness categories include missing authentication for a critical function, authentication bypass by spoofing, hard-coded credentials, weak authentication, inadequate limits on login attempts, reliance on untrusted inputs in security decisions, and use of sensitive information in GET-request query strings.

Cybersecurity briefing depicts a health tracker and app with exposed session tokens, critical vulnerabilities, and account takeover risks.Eight CVEs point to an account and data-security problem​

The affected products are made by Quanovate Tech Inc., which operates as Mira and Mira Care. Mira markets its monitor and companion app for tracking fertility, ovulation, menstrual cycles, hormone trends, perimenopause, and related health information. The Google Play listing says the Android app can collect personal information and health-and-fitness data, while Mira’s own materials describe the monitor as syncing results to the app over Bluetooth.

CISA assigns the same eight CVE identifiers to both the monitor firmware and Android app:

  • CVE-2026-66875
  • CVE-2026-66098
  • CVE-2026-67558
  • CVE-2026-67568
  • CVE-2026-68067
  • CVE-2026-66340
  • CVE-2026-64934
  • CVE-2026-66832

The advisory does not publicly map each CVE to a single flaw category or describe an attack chain. It instead gives a combined impact statement: successful exploitation could disclose health-profile information and session tokens, permit unauthorized health-information changes, cause denial of service, or allow an attacker to take over user accounts.

That combination deserves more attention than the generic “medical device” label may suggest. A compromised account is not limited to a device reading; Mira’s Android application includes cycle records, hormone values, symptoms, medication logging, basal body temperature entries, and partner-sharing features. Depending on how an individual uses the app, those records can reveal fertility treatment, pregnancy planning, cycle timing, hormone therapy, or other sensitive personal circumstances.

Mira says in a privacy-focused article updated in February that personal health data is confidential and “never sold or shared with third parties.” CISA’s advisory does not accuse Mira of deliberately sharing data. It raises a different concern: whether an unauthenticated or weakly authenticated attacker can gain access despite the user’s expectation that those records remain private.

The version numbers leave owners unable to verify their status​

The most consequential discrepancy is in the Android versioning. CISA’s August 11 advisory names Mira Android App 4.5.15.4 as affected. Google Play’s public listing for “Mira Fertility & Cycle Tracker,” however, shows version 3.5.17 as its current release and says it was updated on July 3, 2026.

Those two numbers may refer to different release schemes — for example, a public marketing version versus an internal build number — but neither CISA nor Mira’s public-facing material explains the relationship. Users who open Google Play therefore cannot simply compare the advisory’s affected version with the version displayed in their app and reach a defensible answer.

The same issue exists, although less sharply, with the monitor firmware. Mira’s support documentation tells users to find the analyzer’s software version in the app under Profile, then “My Devices,” then “Mira Analyzer.” That support page describes version families in the format V01.06.xx.xx and V01.07.xx.xx and says units can be updated to version 01.07.01.12 or later. CISA’s affected version is rendered as 1.7.1.47, which looks compatible with that family but is formatted differently.

The distinction is more than cosmetic. A security advisory works only when an owner can identify an affected installation and determine the available fix. Here, a Mira user may see 3.5.17 in Google Play and V01.07.01.xx in the app, while the government advisory lists 4.5.15.4 and 1.7.1.47. Until Quanovate publishes a conversion between those identifiers and names the remediated releases, owners cannot independently establish whether they are protected.

CISA’s standard network guidance does not solve the consumer-device question​

CISA recommends minimizing network exposure, keeping devices behind firewalls, segmenting networks, and using VPNs for remote access where needed. Those are sensible practices in the industrial-control environments for which CISA’s advisory template is designed. They are also largely beside the point for a consumer Bluetooth hormone monitor paired to a personal Android phone.

A home user cannot realistically place the Mira service behind an enterprise firewall or segment the vendor’s cloud infrastructure. Nor can a VPN correct hard-coded credentials, insufficient login protection, a server-side authorization gap, or a session-token leak in an app or web API. The remediation has to come from the vendor through corrected firmware, a corrected Android release, server-side changes, or some combination of all three.

The public record does not yet say which of those paths is required. CISA’s notice does not identify a firmware update procedure, tell users to reset passwords, recommend revoking active sessions, or say whether Bluetooth pairing must be re-established after an update. It does not state whether exploitation requires proximity to the monitor, access to the same local network, knowledge of a victim account, or interaction with a malicious link.

Those omissions matter when interpreting the 9.8 score. CVSS 9.8 signals a critical severity assessment, but CISA has not published the attack vector or per-CVE scoring details in the advisory. Readers should therefore avoid assuming that every Mira owner is exposed to the same attack path at all times. The documented risk is serious; the operational conditions remain undisclosed.

What Mira users and Android administrators can do now​

Mira has not published a corresponding public security bulletin or a version-by-version remediation notice that was discoverable when CISA released its alert. No independent outlet appears to have reported a patch timeline or confirmed whether a corrected Android build is rolling out.

Users should take the following practical steps while that remains unresolved:

  • Update the Mira app through Google Play and accept any pending Mira monitor firmware update offered through the app, but retain screenshots of the versions shown before and after updating.
  • Check the Mira app’s device page for the analyzer software version rather than relying only on the Android app version displayed by Google Play.
  • Use a unique password for the Mira account, and change it if it is reused anywhere else. This reduces the damage if session or authentication weaknesses are combined with credentials exposed in another breach.
  • Review shared access, including partner-sharing arrangements, and remove access that is no longer needed.
  • Do not treat a VPN, router change, or Bluetooth toggle as a substitute for a vendor fix. Those controls may reduce some exposure but cannot repair flaws in authentication or cloud-service design.
  • Watch for a vendor communication that explicitly states the affected and fixed firmware versions, the affected and fixed Android versions, and whether users need to take account-level actions such as password resets or re-pairing devices.

For organizations that issue Android phones to employees or support patients using mobile health applications, this should be treated as a privacy and account-security advisory, not as an excuse to deploy industrial-control-style network controls. Confirm whether Mira is installed on managed Android devices, ensure automatic app updates are enabled where policy permits, and avoid making claims to users that the current public Play version resolves CISA’s listed CVEs until Mira says so plainly.

The researchers credited by CISA — Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University’s SPQR Lab — reported the issues to Quanovate Tech. CISA’s August 11 publication establishes that the vendor was notified and that the affected firmware and Android app were identified. What has not been established publicly is the one answer Mira users need: which exact versions are safe to run today.