Executive summary

CISA has issued medical advisory ICSMA-26-223-01 warning of eight vulnerabilities in the Mira hormone monitor (Quanovate Tech Inc.) and its Android mobile app. The device is a quantitative fertility monitor used by assisted reproduction clinics and by consumers to measure LH, E3G (estriol-glucuronide) and PdG (pregnanediol-glucuronide) in urine, with BLE sync to the phone. Affected versions are Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4. Eight CVEs cover those products: CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934 and CVE-2026-66832. Several vectors are exploitable without authentication or user interaction, and one (CVE-2026-68067) reaches CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (network, no privileges, no UI, high impact on confidentiality, integrity and availability). Mitigation is available: update to iOS v3.5.18 / Android v4.5.18 (firmware v01.07.01.53 is pushed via the app). Critical Infrastructure Sector: Healthcare and Public Health.

Key points

  • 8 CVEs across the same product/firmware pair: combination of BLE authentication bypass, buffer issues, unauthorized data read and measurement manipulation. CVE-2026-68067 with AV:N (network-reachable) and full C/I/A impact is the most severe.
  • Clinical data at risk: hormone values synced to the app allow inference of fertility status, menstrual cycle phase, early pregnancies and pregnancy losses, plus measurement timestamps correlating with sexual activity and reproductive planning. A special category of data under GDPR Art. 9.
  • BLE vector without documented pairing: at least CVE-2026-66875 enables access with AV:A/PR:N/UI:N/S:U/C:H/I:H/A:H — i.e., adjacent (BLE), unauthenticated, no user interaction, full compromise.
  • Android app vulnerable: the BLE surface is complemented by app-side logic (payload parsing, persistence, cloud sync). An attacker in BLE proximity can inject false hormone readings that lead to incorrect clinical decisions (ovulation interpretation, targeted intercourse indication, assisted reproduction decisions).
  • Mitigation is published and available: app v4.5.18 (Android) and v3.5.18 (iOS) are already published. Firmware v01.07.01.53 is pushed by the app on connection. No device return needed, but update is mandatory.
  • Implication for clinics: fertility clinics and gynaecology practices that recommend Mira or receive synced data must verify the installed version on their patients and reinforce the advice channel (do not base clinical decisions solely on the app).

Regulatory implications

FDA (US)

Quanovate markets Mira in the US under the Wellness / Class II category depending on claims. The published update, although after discovery, satisfies the post-market surveillance and patching obligations of the FDA 2023 guidance. Under 21 CFR Part 806, the manufacturer must document the correction as a field action (no formal recall required if the update is distributed OTA with no residual risk). FDA may audit the responsible disclosure process.

MDR (EU)

Under MDR Art. 87, a vulnerability affecting clinical data generated by an active medical device (quantitative measurement) constitutes a notifiable incident if it could have impacted clinical decisions or exposed health data. Quanovate must have evaluated whether any of the 8 CVEs was exploited in production and notified the Member State competent authority (AEMPS in Spain, MHRA in the UK, etc.) within ≤15 days.

GDPR and sensitive data

Fertility measurements are health data (Art. 9.1 GDPR) and data concerning sexual life (Art. 9.1 GDPR, second indent). An unauthorised exfiltration triggers the obligation to notify the supervisory authority within ≤72h (Art. 33) and, if there is high risk to data subjects’ rights, communicate to the data subject (Art. 34). Mira stores data in Quanovate’s cloud: the EDPB can assess whether the manufacturer has complied with privacy by design (Art. 25) given that the transport-layer and app CVEs impacted confidentiality.

NIS2 and ENS

For European fertility clinics (essential service operators in some Member States), the vulnerability activates the duty of supply chain risk assessment (Art. 21 NIS2) and of medical device inventory connected to corporate networks (ENS HIGH [op.cont.4]). Even if the device belongs to the patient, the synced data may reach the centre’s electronic health record.

HIPAA (US)

If the clinic receives Mira data in its EHR, the hormone values form part of PHI and a device compromise triggers §164.404 (patient notification) if exfiltration is confirmed.

Recommendation

Immediate actions within the next 72 hours: (1) Notify patients using Mira to update to Android v4.5.18 / iOS v3.5.18 as soon as possible — firmware v01.07.01.53 updates automatically when the app is opened with the device nearby; (2) Verify installed version on every device in the centre’s fleet (corporate health, clinical research, samples in custody); (3) Do not base clinical decisions solely on Mira readings during the vulnerability window; review protocols to confirm measurements with a second source (blood lab) where applicable; (4) Block unauthorized BLE pairings and monitor unknown BLE advertisements in proximity; (5) Threat hunt over app and Mira cloud logs for anomalous readings (impossible timestamps, out-of-range physiological values, unauthorized account changes); (6) GDPR compliance: assess whether Art. 33 notification applies for potential exfiltration of fertility data; (7) Coordinate with Quanovate: confirm update receipt, closed responsible disclosure plan, public disclosure timeline; (8) SBOM inventory: request SBOM from Quanovate to integrate firmware/app dependencies into the corporate vulnerability analysis.


Source: CISA ICSMA-26-223-01 — Mira Hormone Monitor, Mira Android App

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.