Core Lightning Security Vulnerability: What Node Operators Must Do Now

If you run your own Lightning node on the Core Lightning software, exactly one task is due today: the update to version 26.06.7. Blockstream says it shipped this release on August 28, 2026. It closes several confirmed security vulnerabilities, and every older release has counted as unsupported since then. If you cannot update straight away, restart the node with the --offline switch instead. Either takes a few minutes, and either is more effective than the reaction most people reach for first: switching the machine off.
If you hold Bitcoin on an exchange, in an ordinary wallet or in an app without running a node yourself, the warning does not concern you directly. What is meant is the machine that manages your payment channels. Anyone who runs none has nothing to update. It is still worth a look: the episode shows how quickly a reported programming error turns into a deadline with a date, and it is repeating itself at short intervals right now.
What happened: Core Lightning confirms vulnerabilities and ships an emergency update
Core Lightning, CLN for short, is one of several software implementations of the Lightning network. The Lightning network is a second layer above the Bitcoin blockchain: two parties jointly lock an amount in a transaction and then settle between themselves as often as they like, without writing each payment into the blockchain individually. That locked connection is called a payment channel. The software that manages such a channel, monitors it and defends it in a dispute is called a node.
โฆ Continue reading the full article at the original source below.



