Core Lightning, an open-source implementation for operating Bitcoin Lightning Network nodes, has called on operators to upgrade their software immediately following reports that attackers are actively targeting outdated versions.
Call for immediate action
On Friday, the Core Lightning team warned users running version 26.06.7 or earlier to switch to the latest release without delay. The team stated, “Urgent security update: If you’re running version 26.06.7 or earlier, please upgrade to the latest release as soon as possible.”
Core Lightning did not disclose the specific vulnerabilities attackers are exploiting or the full scope of the risks posed to node operators. However, the urgency of the recommendation underscored the seriousness of the threat.
Security vulnerabilities and recent updates
The latest update follows an incident in mid-September when Core Lightning began investigating reports of potential flaws involving experimental features that could put user funds at risk. On September 22, the development team released version 26.06.8, which included crucial bug fixes and security patches.
In the release notes, Core Lightning credited the Bitcoin Red Team, a security-focused group within the Bitcoin ecosystem, along with a dozen other experts and anonymous sources who reported vulnerabilities.
The changelog revealed several mitigated issues, including bugs that could crash sender nodes, exhaust server memory through its REST interface, and a channel-closing flaw that could potentially result in lost funds through penalties.
To minimize the risk of further attacks while users upgraded, Core Lightning withheld the publication of some software tests, making it more challenging for malicious actors to reverse-engineer the patched vulnerabilities.
Mini dictionary: Core Lightning is a leading open-source project providing node software for the Bitcoin Lightning Network, enabling scalable and fast transactions.
Recent vulnerability reports
In August, Core Lightning began addressing an increase in reports of Common Vulnerabilities and Exposures (CVEs), many of which were generated by automated AI tools. Shortly thereafter, the development team released version 26.06.7 to remediate the confirmed security issues.
The project continues to prioritize the rapid resolution of security threats, regularly coordinating fixes and collaborating with researchers across the ecosystem.
On Friday, Core Lightning emphasized that operators using older versions must upgrade immediately, noting the escalation in security threats to unpatched nodes.




