CISA-linked disclosures detailed serious vulnerabilities in two consumer health-device ecosystems: Quanovate Tech's Mira Hormone Monitor and Pulsetto Vagus Nerve Stimulator. In Mira, researchers identified 20 issues, including CVE-2026-67568 and CVE-2026-66875, affecting firmware 1.7.1.47 and Android app 4.5.15.4. The flaws include hard-coded credentials that could expose reproductive health profiles over internet-connected hosts, and missing authentication over Bluetooth Low Energy that could let a nearby attacker silently rebind a device to an attacker-controlled account, read hormone measurements in cleartext, trigger denial of service, and track users via a static BLE address. The reported impact includes theft, forgery, deletion, or destruction of sensitive fertility data, with potential disruption to treatment decisions.
Pulsetto's firmware was separately assigned CVE-2026-18844 for hidden BLE functionality that accepts undocumented commands without authentication or encryption whenever the device is powered on. The issue could allow an adjacent attacker to alter stimulation settings or disable electrical safety mechanisms, creating high integrity and availability risk. Quanovate released remediations including firmware 01.07.01.53 and Android app 4.5.18 for Mira, while CISA said Pulsetto had not responded to outreach and advised users to contact the vendor for remediation details. No evidence of active exploitation was reported for the Mira issues, and CISA's SSVC data for Pulsetto listed exploitation as none.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
CISA added SSVC decision data for CVE-2026-18844, marking exploitation as none, automatable as no, and technical impact as partial. References were also added to a CISA medical advisory and a CSAF record.
CISA received CVE-2026-66875 affecting Mira firmware 1.7.1.47 and Android app 4.5.15.4. The flaw allows unauthenticated attackers within BLE range to rebind devices, extract measurements, trigger denial of service, and track users.
CISA received CVE-2026-67568 covering Mira Firmware 1.7.1.47 and Mira Android App 4.5.15.4. The vulnerability allows read and write access to reproductive health profiles from internet-connected hosts.
The CVE record for CVE-2026-18844, affecting the Pulsetto Vagus Nerve Stimulator firmware, was received by ics-cert@hq.dhs.gov. The issue involves undocumented BLE commands accepted without authentication or encryption.
A public report described critical vulnerabilities in the Mira Hormone Monitor ecosystem and the Pulsetto Vagus Nerve Stimulator. It noted no evidence of actual or attempted exploitation of the Mira vulnerabilities and said Pulsetto had not responded to CISA outreach.
Quanovate Tech released remediation updates for Mira, including firmware version 01.07.01.53, Android app version 4.5.18, and iOS app version 3.5.18. These updates addressed vulnerabilities affecting firmware 1.7.1.47 and Android app 4.5.15.4.
HIPAA Journal reported that Northeastern University SPQR Lab identified 20 vulnerabilities in the Mira hormone monitor ecosystem and coordinated disclosure with Quanovate Tech and CISA. Quanovate Tech completed two rounds of remediation before the findings were previewed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.