AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66875

HIGH · CVSS 8.8 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Mira hormone monitor device firmware is vulnerable to remote unauthenticated attacks within Bluetooth Low Energy (BLE) range, allowing attackers to rebind the device to their own account and access sensitive hormone measurement data in cleartext. Additionally, attackers can induce a denial-of-service through malformed commands and track users due to a static BLE address that does not change. Healthcare organizations and users of the Mira device should prioritize addressing this vulnerability to protect sensitive health data and ensure device integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66875
Severity
HIGH
CVSS
8.8
EPSS
0.24%

Original NVD Description

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.