THE CISA has disclosed eight vulnerabilities in the Mira Hormone Monitor and its Android app, with the most severe being CVE-2026-68067, which has a critical CVSS score of 9.8. This vulnerability allows remote attackers to control user accounts by bypassing cloud login authentication. No public exploitation has been reported. The vulnerabilities include issues related to weak authentication, hard-coded credentials, and improper authentication methods.
Important Note: Users are urged to patch their devices and apps to mitigate potential risks, as the personal nature of the data tracked by the device raises significant safety concerns.