Core Lightning Security Update Urges Immediate Node Upgrade

Wait 5 sec.

TLDR:Core Lightning 26.06.7 fixes multiple vulnerabilities while technical details remain under a 14-day embargo.Developers urged every Core Lightning node runner to upgrade immediately and avoid waiting for Docker images.AI-generated vulnerability reports increased the volume and pace of security findings across open-source Bitcoin projects.Signed binaries let operators upgrade and verify releases before full vulnerability details become publicly available.Core Lightning has released version 26.06.7, urging every node runner to upgrade immediately. The update fixes multiple vulnerabilities reported during the past three weeks.Developers will keep technical details and source code private for 14 days. The embargo aims to prevent attackers from exploiting unpatched nodes before operators complete upgrades.Core Lightning Security Update Starts Two-Week EmbargoThe release arrives amid a rise in AI-generated vulnerability reports targeting open-source Bitcoin projects.According to Core Lightning, increasingly capable AI models have increased both the volume and pace of security reports.The development team received and triaged several vulnerability reports from multiple sources. Developers then resolved the issues before compiling the emergency point release.Core Lightning said it withheld technical details because attackers could reverse-engineer the fixes. That process could expose node operators who delay their upgrades.The embargo will last 14 days from the release. Developers will publish the full vulnerability details and source code afterward.Core Lightning previously warned operators about the upcoming security release. Blockonomi reported that developers had received several AI-generated reports within a 10-day period.The earlier report also said developers planned to distribute signed binaries before publishing source-level details. No confirmed fund losses or active exploitation had been reported.The latest release now puts that plan into action. Node runners can access the binaries while developers maintain the temporary disclosure restrictions.Core Lightning 26.06.7 is out and recommended for every node runner.It fixes vulnerabilities reported over the past three weeks, during a sharp rise in AI-generated reports across open source Bitcoin. Details stay under embargo for two weeks, then all published.…— Core Lightning (@Core_LN) August 28, 2026Core Lightning 26.06.7 Upgrade Instructions Target Node RunnersCore Lightning has told all node runners not to delay the upgrade. The team specifically warned users against waiting for Docker images.Docker images were unavailable when the release launched. Developers instead directed operators to use the available tarballs for immediate upgrades.The upgrade process requires downloading and verifying the appropriate platform tarball. Operators then unpack it over their existing installation and restart lightningd.Core Lightning said the update requires no manual database migration. The software automatically handles the required migration steps during startup.The release also includes signed manifests for binary verification. Operators can check file integrity through checksums and verify signatures with GPG.The project listed separate signed files for amd64 and arm64 builds. Maintainers provided signing fingerprints to help users verify authentic releases.The security update follows a broader period of change for Bitcoin’s Lightning Network. Blockonomi reported Lightning capacity had fallen to 3,998 BTC from 5,891 BTC in December 2025.That represented a 32.1% decline during the period. Meanwhile, Core Lightning’s latest stable public release before this update was version 26.06.6.Version 26.09 remains scheduled for September, according to the earlier report. For now, version 26.06.7 remains the immediate priority for Core Lightning node operators.The post Core Lightning Security Update Urges Immediate Node Upgrade appeared first on Blockonomi.