Core Lightning, the open-source software for Bitcoin's Lightning Network nodes, on Friday urged operators running version 26.06.7 or earlier to update immediately following reports of attacks targeting unpatched nodes. The team did not specify which vulnerabilities were being exploited or the potential impact.

Release 26.06.8: patches and fixes

On September 16, Core Lightning announced it was investigating a potential issue in experimental features that could affect user funds, and about six days later released version 26.06.8. The update, published on September 22, included bug fixes and patches for "vulnerabilities responsibly disclosed by several sources." The release notes mention Bitcoin Red Team and 12 other named contributors, as well as anonymous reporters.

Among the fixes were bugs that could cause sender nodes to crash, memory exhaustion in the REST interface, and a channel closure error that could result in users losing funds as a penalty. Some tests were deliberately withheld from publication to make reverse engineering of the vulnerabilities more difficult while operators updated.

August: wave of AI-CVE and release 26.06.7

In August, Core Lightning reported working on a coordinated fix after reviewing a large number of AI-generated CVE reports in recent weeks. Two days later, version 26.06.7 was released, addressing the confirmed vulnerabilities.